TYPO3 Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2023-30451 - Vulnerability Database

TYPO3 Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2023-30451

Medium
Reference: CVE-2023-30451
Title: TYPO3 Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
Overview:

In TYPO3 11.5.24 the filelist component allows attackers (who have access to the administrator panel) to read arbitrary files via directory traversal in the baseuri field as demonstrated by POST /typo3/record/edit with ../../../ in datasys_file_storagedatasDEFlDEFbasePathvDEF.