Vulnerability Details CVE-2011-4904
TYPO3 before 4.4.9 and 4.5.x before 4.5.4 does not apply proper access control on ExtDirect calls which allows remote attackers to retrieve ExtDirect endpoint services.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 48.2%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2011-4904
-
cpe:2.3:a:typo3:typo3:4.4.0
-
cpe:2.3:a:typo3:typo3:4.4.1
-
cpe:2.3:a:typo3:typo3:4.4.2
-
cpe:2.3:a:typo3:typo3:4.4.3
-
cpe:2.3:a:typo3:typo3:4.4.4
-
cpe:2.3:a:typo3:typo3:4.4.5
-
cpe:2.3:a:typo3:typo3:4.4.6
-
cpe:2.3:a:typo3:typo3:4.4.7
-
cpe:2.3:a:typo3:typo3:4.4.8
-
cpe:2.3:a:typo3:typo3:4.5.0
-
cpe:2.3:a:typo3:typo3:4.5.1
-
cpe:2.3:a:typo3:typo3:4.5.2
-
cpe:2.3:a:typo3:typo3:4.5.3