VYPR
High severity8.1NVD Advisory· Published Jan 23, 2017· Updated Jun 17, 2026

CVE-2016-5091

CVE-2016-5091

Description

Extbase in TYPO3 4.3.0 before 6.2.24, 7.x before 7.6.8, and 8.1.1 allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted Extbase action.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
typo3/cms-extbasePackagist
< 6.2.246.2.24
typo3/cms-extbasePackagist
>= 7.0, < 7.6.87.6.8

Affected products

20
  • ghsa-coords
    Range: < 6.2.24
  • TYPO3/Typo319 versions
    cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*+ 18 more
    • cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*range: <=6.2.23
    • cpe:2.3:a:typo3:typo3:7.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:7.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:7.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:7.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:7.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:7.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:7.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:7.5.0:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:7.6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:7.6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:7.6.2:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:7.6.3:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:7.6.4:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:7.6.5:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:7.6.6:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:7.6.7:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:7.6.8:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:8.1.1:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.