Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. typo3/cms-core
  4. ›
  5. GHSA-hjx5-v9xg-7h25

GHSA-hjx5-v9xg-7h25: TYPO3 Denial of Service in Frontend Record Registration

May 30, 2024

TYPO3’s built-in record registration functionality (aka “basic shopping cart”) using recs URL parameters is vulnerable to denial of service. Failing to properly ensure that anonymous user sessions are valid, attackers can use this vulnerability in order to create an arbitrary amount of individual session-data records in the database.

References

  • github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/2018-12-11-7.yaml
  • github.com/TYPO3-CMS/core
  • github.com/TYPO3-CMS/core/commit/5a44f93e9233e8f72159f9a67db26ed4bd5a10e0
  • github.com/advisories/GHSA-hjx5-v9xg-7h25
  • typo3.org/security/advisory/typo3-core-sa-2018-012

Code Behaviors & Features

Detect and mitigate GHSA-hjx5-v9xg-7h25 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 7.0.0 before 7.6.32, all versions starting from 8.0.0 before 8.7.21

Fixed versions

  • 8.7.21
  • 7.6.32

Solution

Upgrade to versions 7.6.32, 8.7.21 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-770: Allocation of Resources Without Limits or Throttling

Source file

packagist/typo3/cms-core/GHSA-hjx5-v9xg-7h25.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:16:09 +0000.