sr_freecap for Typo3 RCE Vulnerability
Critical severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Sep 26, 2023
Package
Affected versions
>= 2.5.0, < 2.5.3
< 2.4.6
Patched versions
2.5.3
2.4.6
Description
Published by the National Vulnerability Database
Oct 16, 2019
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Jul 18, 2023
Last updated
Sep 26, 2023
The sr_freecap (aka freeCap CAPTCHA) extension 2.4.5 and below and 2.5.2 and below for TYPO3 fails to sanitize user input, which allows execution of arbitrary Extbase actions, resulting in Remote Code Execution.
References