The slub_events (aka SLUB: Event Registration) extension through 3.0.2 for TYPO3 allows uploading of arbitrary files to the webserver. For versions 1.2.2 and below, this results in Remote Code Execution. In versions later than 1.2.2, this can result in Denial of Service, since the web space can be filled up with arbitrary files.
References
Link | Resource |
---|---|
https://extensions.typo3.org/extension/slub_events | Third Party Advisory |
https://typo3.org/security/advisory/typo3-ext-sa-2019-017/ | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2019-10-16T18:37:38
Updated: 2019-10-16T18:37:38
Reserved: 2019-09-22T00:00:00
Link: CVE-2019-16700
JSON object: View
NVD Information
Status : Analyzed
Published: 2019-10-16T19:15:15.927
Modified: 2019-10-31T19:03:00.213
Link: CVE-2019-16700
JSON object: View
Redhat Information
No data.
CWE