CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-55892: Potential Open Redirect via Parsing Differences in TYPO3

4.8 CVSS

Description

TYPO3 is a free and open source Content Management Framework. Applications that use `TYPO3\CMS\Core\Http\Uri` to parse externally provided URLs (e.g., via a query parameter) and validate the host of the parsed URL may be vulnerable to open redirect or SSRF attacks if the URL is used after passing the validation checks. Users are advised to update to TYPO3 versions 9.5.49 ELTS, 10.4.48 ELTS, 11.5.42 LTS, 12.4.25 LTS, 13.4.3 which fix the problem described. There are no known workarounds for this vulnerability.

Classification

CVE ID: CVE-2024-55892

CVSS Base Severity: MEDIUM

CVSS Base Score: 4.8

Affected Products

Vendor: TYPO3

Product: typo3

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.06% (probability of being exploited)

EPSS Percentile: 28.03% (scored less or equal to compared to others)

EPSS Date: 2025-02-12 (when was this score calculated)

References

https://github.com/TYPO3/typo3/security/advisories/GHSA-2fx5-pggv-6jjr
https://typo3.org/security/advisory/typo3-core-sa-2025-002

Timeline