CVE-2012-1605
Typo3 Extbase Framework Unsafe Deserialization
EPSS 0.94%
Description
The Extbase Framework in TYPO3 4.6.x through 4.6.6, 4.7, and 6.0 unserializes untrusted data, which allows remote attackers to unserialize arbitrary objects and possibly execute arbitrary code via vectors related to "a missing signature (HMAC) for a request argument."
How to fix CVE-2012-1605
To remediate CVE-2012-1605, upgrade the affected package to a fixed version below.
- Packagist/typo3/cms—upgrade to 4.6.7 or later
Is CVE-2012-1605 being exploited?
Low — EPSS is 0.9%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 4.6, < 4.6.7