296,172
Total vulnerabilities in the database
Due to a missing file extension in the fileDenyPattern, backend user are allowed to upload *.pht files which can be executed in certain web server setups. The new default fileDenyPattern is the following, which might have been overridden in the TYPO3 Install Tool.
\.(php[3-7]?|phpsh|phtml|pht)(\..*)?$|^\.htaccess$
Software | From | Fixed in |
---|---|---|
![]() |
7.6.0 | 7.6.22 |
![]() |
8.0.0 | 8.7.5 |