{"id":"GHSA-v6xv-rmqc-wcc8","summary":"Typo3 Open Redirect In Frontend Rendering","details":"The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, allows remote attackers to change URLs to arbitrary domains.\n\nAn attacker could forge a request which modifies anchor only links on the homepage of a TYPO3 installation such that they point to arbitrary domains, if the configuration option `config.prefixLocalAnchors` is used with any possible value. TYPO3 versions 4.6.x and higher are only affected if the homepage is not a shortcut to a different page. As an additional pre-condition, URL rewriting must be enabled in the web server (which it typically is) when using extensions like realurl or cooluri.\n\nInstallations where `config.absRefPrefix` is additionally set to any value are not affected by this vulnerability.\n\nExample of affected configuration:\n\n```php\nconfig.absRefPrefix =\nconfig.prefixLocalAnchors = all \npage = PAGE \npage.10 = TEXT \npage.10.value = \u003ca href=\"#skiplinks\"\u003eSkiplinks\u003c/a\u003e \n.htaccess:\n\nRewriteCond %{REQUEST_FILENAME} !-f \nRewriteCond %{REQUEST_FILENAME} !-d \nRewriteCond %{REQUEST_FILENAME} !-l \nRewriteRule .* index.php [L] \n```","aliases":["CVE-2014-9508"],"modified":"2024-11-30T05:35:31.018112Z","published":"2022-05-17T03:45:52Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-08-16T22:31:44Z","nvd_published_at":"2015-01-04T21:59:00Z","cwe_ids":["CWE-59"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-9508"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/CVE-2014-9508.yaml"},{"type":"WEB","url":"https://typo3.org/security/advisory/typo3-core-sa-2014-003"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-updates/2016-08/msg00106.html"},{"type":"WEB","url":"http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2014-003"}],"affected":[{"package":{"name":"typo3/cms","ecosystem":"Packagist","purl":"pkg:composer/typo3/cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.5.0"},{"fixed":"4.5.39"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-v6xv-rmqc-wcc8/GHSA-v6xv-rmqc-wcc8.json"}},{"package":{"name":"typo3/cms","ecosystem":"Packagist","purl":"pkg:composer/typo3/cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.6.0"},{"fixed":"6.2.9"}]}],"versions":["6.2.0","6.2.1","6.2.2","6.2.3","6.2.4","6.2.5","6.2.6","6.2.7","6.2.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-v6xv-rmqc-wcc8/GHSA-v6xv-rmqc-wcc8.json"}},{"package":{"name":"typo3/cms","ecosystem":"Packagist","purl":"pkg:composer/typo3/cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.0.0"},{"fixed":"7.0.2"}]}],"versions":["7.0.0","7.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-v6xv-rmqc-wcc8/GHSA-v6xv-rmqc-wcc8.json"}}],"schema_version":"1.9.0"}