CVE-2013-4250: TYPO3
Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.
The (1) file upload component and (2) File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.3 do not properly check file extensions, which allow remote authenticated editors to execute arbitrary PHP code by uploading a .php file.
Affected products
- TYPO3 TYPO3: version 6.0 only; version 6.0.1 only; version 6.0.2 only; version 6.0.3 only; version 6.0.4 only; version 6.0.5 only; …
Published 2014-05-20. Last modified 2026-06-16.