VYPR
Moderate severityNVD Advisory· Published Sep 5, 2012· Updated Apr 29, 2026

CVE-2012-3527

CVE-2012-3527

Description

view_help.php in the backend help system in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to unserialize arbitrary objects and possibly execute arbitrary PHP code via an unspecified parameter, related to a "missing signature (HMAC)."

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
typo3/cmsPackagist
>= 4.5.0, < 4.5.194.5.19
typo3/cmsPackagist
>= 4.6.0, < 4.6.124.6.12
typo3/cmsPackagist
>= 4.7.0, < 4.7.44.7.4

Affected products

3
  • cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
    Range: >=4.5.0,<4.5.19
  • cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.