Failing to properly check user permission on file storages, editors could gain knowledge of protected storages and its folders as well as using them in a file collection being rendered in the frontend. A valid backend user account is needed to exploit this vulnerability.
| Software | From | Fixed in |
|---|---|---|
typo3 / cms
|
7.6.0 | 7.6.22 |
typo3 / cms
|
8.0.0 | 8.7.5 |