PT-2026-81224 · Typo3 · Typo3
CVSS v4.0
7.7
High
| Vector | AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined (affected versions not specified)
Description
The indexer of the extension uses the PHP
unserialize() function to process field values returned by content object rendering when transferring multi-value data for SOLR CLASSIFICATION, SOLR MULTIVALUE, and SOLR RELATION content object types. This occurs instead of using a safe data format. If user-generated content stored in the TYPO3 database reaches an indexed field, it creates a PHP Object Injection surface, which allows an attacker to inject malicious serialized objects into the application.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Typo3