CVE-2013-7080

Publication date 23 December 2013

Last updated 24 July 2024


Ubuntu priority

The creating record functionality in Extension table administration library (feuser_adminLib.inc) in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, and 6.0.0 through 6.0.11 allows remote attackers to write to arbitrary fields in the configuration database table via crafted links, aka “Mass Assignment.”

Status

Package Ubuntu Release Status
typo3-src 17.04 zesty Not in release
16.10 yakkety Not in release
16.04 LTS xenial Not in release
15.10 wily Not in release
15.04 vivid
Not affected
14.10 utopic
Not affected
14.04 LTS trusty Not in release
13.10 saucy Ignored end of life
13.04 raring
Fixed 4.5.19+dfsg1-5+wheezy2build0.13.04.1
12.10 quantal Ignored end of life
12.04 LTS precise Ignored end of life
10.04 LTS lucid Ignored end of life