TYPO3 before 13.3.1 allows denial of service (interface error) in the Bookmark Toolbar (ext:backend), exploitable by an administrator-level backend user account via manipulated data saved in the bookmark toolbar of the backend user interface. The fixed versions are 10.4.46 ELTS, 11.5.40 LTS, 12.4.21 LTS, and 13.3.1.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| typo3/cms-backend(Packagist) | 13.0.0 | 13.3.1 | N/A |
| typo3/cms-backend(Packagist) | 12.0.0 | 12.4.21 | N/A |
| typo3/cms-backend(Packagist) | 11.0.0 | 11.5.40 | N/A |
| typo3/cms-backend(Packagist) | 10.0.0 | 10.4.46 | N/A |
CVSS Metrics