TYPO3 Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2023-30451
Reference:
CVE-2023-30451
Title:
TYPO3 Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
Overview:
In TYPO3 11.5.24 the filelist component allows attackers (who have access to the administrator panel) to read arbitrary files via directory traversal in the baseuri field as demonstrated by POST /typo3/record/edit with ../../../ in datasys_file_storagedatasDEFlDEFbasePathvDEF.