It has been discovered, that editors with access to the file list module could list all files names and folder names in the root directory of a TYPO3 installation. Modification of files, listing further nested directories or retrieving file contents was not possible. A valid backend user account is needed to exploit this vulnerability.
| Software | From | Fixed in |
|---|---|---|
typo3 / cms
|
6.2.0 | 6.2.14 |
typo3 / cms
|
7.0.0 | 7.3.1 |