VYPR
Moderate severityNVD Advisory· Published Sep 4, 2012· Updated Apr 29, 2026

CVE-2012-1605

CVE-2012-1605

Description

The Extbase Framework in TYPO3 4.6.x through 4.6.6, 4.7, and 6.0 unserializes untrusted data, which allows remote attackers to unserialize arbitrary objects and possibly execute arbitrary code via vectors related to "a missing signature (HMAC) for a request argument."

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
typo3/cmsPackagist
>= 4.6, < 4.6.74.6.7
typo3/cmsPackagist
>= 4.4.0, < 4.4.144.4.14
typo3/cmsPackagist
>= 4.5.0, < 4.5.144.5.14

Affected products

11
  • TYPO3/Typo310 versions
    cpe:2.3:a:typo3:typo3:4.6:*:*:*:*:*:*:*+ 9 more
    • cpe:2.3:a:typo3:typo3:4.6:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.6.2:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.6.3:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.6.4:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.6.5:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.6.6:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.7:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.0:*:*:*:*:*:*:*
  • ghsa-coords
    Range: >= 4.6, < 4.6.7

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.