Beveiligingsadvies

CVE-2017-6370

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2017-03-17 17:00:00
Laatst bijgewerkt 2024-08-05 15:25:49
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields.