Skip to content
RequestGuard Vulnerabilities
Pricing

CVE record

CVE-2022-23503

TYPO3 vulnerable to Arbitrary Code Execution via Form Framework

TYPO3 is an open source PHP based web content management system. Versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 are vulnerable to Code Injection. Due to the lack of separating user-submitted data from the internal configuration in the Form Designer backend module, it is possible to inject code instructions to be processed and executed via TypoScript as PHP code. The existence of individual TypoScript instructions for a particular form item and a valid backend user account with access to the form module are needed to exploit this vulnerability. This issue is patched in versions 8.7.49 ELTS, 9.5.38 ELTS, 10.4.33, 11.5.20, 12.1.1.

CVE evidence

Known exploitation

Not listed in fetched KEV catalog

Absence from the fetched catalog does not establish that exploitation has not occurred.

Severity

high

CVSS 8.8 ยท CVSS_V3

Affected packages

2

Supported package records returned by OSV. Vendor and product names are not used to infer matches.

OSV package mapping

Affected open-source packages

PackageEcosystemFixed versions
typo3/cms-corecomposer8.7.49, 9.5.38, 10.4.33, 11.5.20, 12.1.1
typo3/cmscomposer10.4.33, 11.5.20, 12.1.1