CVE-2022-23504 - CVE House
Back to Database
Status published Medium CVE-2022-23504

TYPO3 contains Sensitive Information Disclosure via YAML Placeholder Expressions in Site Configuration

Vulnerability Description

TYPO3 is an open source PHP based web content management system. Versions prior to 9.5.38, 10.4.33, 11.5.20, and 12.1.1 are subject to Sensitive Information Disclosure. Due to the lack of handling user-submitted YAML placeholder expressions in the site configuration backend module, attackers could expose sensitive internal information, such as system configuration or HTTP request messages of other website visitors. A valid backend user account having administrator privileges is needed to exploit this vulnerability. This issue has been patched in versions 9.5.38 ELTS, 10.4.33, 11.5.20, 12.1.1.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-23504

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

typo3
Vulnerable Versions:
>= 9.0.0, < 9.5.38, >= 10.0.0, < 10.4.33, >= 11.0.0, < 11.5.20, >= 12.0.0, < 12.1.1

Timeline

Official Publish: December 14th, 2022
Last Modified: April 21st, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:L

Weaknesses (CWE)