CVE-2013-7080: TYPO3

Medium severity, CVSS 5.8. EPSS: 1.2% chance of exploitation in the next 30 days.

The creating record functionality in Extension table administration library (feuser_adminLib.inc) in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, and 6.0.0 through 6.0.11 allows remote attackers to write to arbitrary fields in the configuration database table via crafted links, aka "Mass Assignment."

Affected products

  • TYPO3 TYPO3: version 6.0 only; version 6.0.1 only; version 6.0.2 only; version 6.0.3 only; version 6.0.4 only; version 6.0.5 only; …

Published 2013-12-23. Last modified 2026-06-17.