| Vulnerability Name: | CVE-2017-6370 (CCN-123580) | ||||||||||||
| Assigned: | 2017-03-17 | ||||||||||||
| Published: | 2017-03-17 | ||||||||||||
| Updated: | 2019-10-03 | ||||||||||||
| Summary: | TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields. | ||||||||||||
| CVSS v3 Severity: | 5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) 4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:U/RC:R)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:U/RC:R)
| ||||||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||
| Vulnerability Type: | CWE-319 | ||||||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2017-6370 Source: BID Type: UNKNOWN 97071 Source: CCN Type: BID-97071 TYPO3 CVE-2017-6370 Information Disclosure Vulnerability Source: XF Type: UNKNOWN typo3-cve20176370-info-disc(123580) Source: CCN Type: faizzaidi GIT Repository TYPO3-v7.6.15-Unencrypted-Login-Request Source: MISC Type: Exploit, Third Party Advisory https://github.com/faizzaidi/TYPO3-v7.6.15-Unencrypted-Login-Request Source: CCN Type: TYPO3 Web site TYPO3 - The Enterprise Open Source CMS | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||