CVE-2024-34537
MEDIUMDescription
TYPO3 before 13.3.1 allows denial of service (interface error) in the Bookmark Toolbar (ext:backend), exploitable by an administrator-level backend user account via manipulated data saved in the bookmark toolbar of the backend user interface. The fixed versions are 10.4.46 ELTS, 11.5.40 LTS, 12.4.21 LTS, and 13.3.1.
Is your site exposed to CVE-2024-34537?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| typo3 | typo3 |
| typo3 | typo3 |
| typo3 | typo3 |
| typo3 | typo3 |
References
Frequently Asked Questions
What is CVE-2024-34537? +
How severe is CVE-2024-34537? +
What products are affected by CVE-2024-34537? +
How do I check if I'm vulnerable to CVE-2024-34537? +
Related Vulnerabilities
Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users …
TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface …
TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface …
Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings …
TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell commands (with the privileges …
TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to versions 10.4.50 …