CVE-2012-3527

medium
Published 2012-09-05 · Modified 2025-04-12
CVSS v3
CVSS v2
4.6
VIR risk
4.6

Description

TYPO3 allows remote authenticated backend users to unserialize arbitrary objects

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-004/

OS impact

OSVersionStatusFixed in
debian debian6.0affected
debian debian7.0affected

Package impact

EcosystemPackageVulnerableFixed
php Packagisttypo3/cms>=4.5.0,<4.5.194.5.19
php Packagisttypo3/cms>=4.6.0,<4.6.124.6.12
php Packagisttypo3/cms>=4.7.0,<4.7.44.7.4

Application impact

VendorProductVersionsFixed
typo3typo3{"startIncluding":"4.5.0","endExcluding":"4.5.19"}4.5.19

References

CWEs

CWE-502

Verify integrity in audit chain (admin only). AS-IS.