296,747
Total vulnerabilities in the database
Due to a missing file extension in the fileDenyPattern, backend user are allowed to upload *.pht files which can be executed in certain web server setups. The new default fileDenyPattern is the following, which might have been overridden in the TYPO3 Install Tool.
\.(php[3-7]?|phpsh|phtml|pht)(\..*)?$|^\.htaccess$
| Software | From | Fixed in |
|---|---|---|
typo3 / cms
|
7.6.0 | 7.6.22 |
typo3 / cms
|
8.0.0 | 8.7.5 |