CVE-2017-6370
Last modified
CVE-2017-6370 is a vulnerability of currently unknown severity. TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields.. EPSS estimates a 0.99% chance of exploitation in the next 30 days.
Description
TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Typo3 | Typo3 | 7.6.15 |
References
- https://github.com/faizzaidi/TYPO3-v7.6.15-Unencrypted-Login-RequestExploit, Third Party Advisory
- https://github.com/faizzaidi/TYPO3-v7.6.15-Unencrypted-Login-RequestExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-6370?
How severe is CVE-2017-6370?
How do I fix CVE-2017-6370?
Are you affected by CVE-2017-6370?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
