CVE-2012-3527
typo3-src - several
EPSS 2.1%
Description
view_help.php in the backend help system in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to unserialize arbitrary objects and possibly execute arbitrary PHP code via an unspecified parameter, related to a "missing signature (HMAC)."
How to fix CVE-2012-3527
To remediate CVE-2012-3527, upgrade the affected package to a fixed version below.
- Debian/typo3-src—upgrade to 4.3.9+dfsg1-1+squeeze5 or later
- Packagist/typo3/cms—upgrade to 4.5.19 or later
Is CVE-2012-3527 being exploited?
Low — EPSS is 2.1%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 4.3.9+dfsg1-1+squeeze5
- >= 4.5.0, < 4.5.19