CVE-2024-34537

TYPO3 before 13.3.1 allows denial of service (interface error) in the Bookmark Toolbar (ext:backend), exploitable by an administrator-level backend user account via manipulated data saved in the bookmark toolbar of the backend user interface. The fixed versions are 10.4.46 ELTS, 11.5.40 LTS, 12.4.21 LTS, and 13.3.1.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*

History

03 Sep 2025, 17:31

Type Values Removed Values Added
First Time Typo3 typo3
Typo3
CPE cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
References () https://github.com/TYPO3/typo3/security/advisories/GHSA-ffcv-v6pw-qhrp - () https://github.com/TYPO3/typo3/security/advisories/GHSA-ffcv-v6pw-qhrp - Vendor Advisory
References () https://typo3.org/security/advisory/typo3-core-sa-2024-011 - () https://typo3.org/security/advisory/typo3-core-sa-2024-011 - Vendor Advisory
References () https://www.mgm-sp.com/cve/denial-of-service-in-typo3-bookmark-toolbar - () https://www.mgm-sp.com/cve/denial-of-service-in-typo3-bookmark-toolbar - Exploit, Third Party Advisory

31 Oct 2024, 17:15

Type Values Removed Values Added
References
  • () https://www.mgm-sp.com/cve/denial-of-service-in-typo3-bookmark-toolbar -

29 Oct 2024, 14:34

Type Values Removed Values Added
Summary
  • (es) TYPO3 anterior a la versión 13.3.1 permite la denegación de servicio (error de interfaz) en la barra de marcadores (ext:backend), que puede ser explotada por una cuenta de usuario de backend de nivel de administrador mediante datos manipulados guardados en la barra de marcadores de la interfaz de usuario de backend. Las versiones corregidas son 10.4.46 ELTS, 11.5.40 LTS, 12.4.21 LTS y 13.3.1.

28 Oct 2024, 17:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.9

28 Oct 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-28 14:15

Updated : 2025-09-03 17:31


NVD link : CVE-2024-34537

Mitre link : CVE-2024-34537

CVE.ORG link : CVE-2024-34537


JSON object : View

Products Affected

typo3

  • typo3