We found results for “


Good to know:


Date: July 12, 2018

In TYPO3 's Form Framework, versions 8.5.0 to 8.7.16 and 9.0.0 to 9.3.0, is vulnerable to Insecure Deserialization when being used with the additional PHP PECL package “yaml”, which is capable of unserializing YAML contents to PHP objects. A valid backend user account as well as having PHP setting "yaml.decode_php" enabled is needed to exploit this vulnerability (which is the default value according to PHP documentation).

Language: PHP

Severity Score

Severity Score

Top Fix


Upgrade Version

Upgrade to version TYPO3_8-7-17,v9.3.1

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privilegs Required (PR): HIGH
User Interaction (UI): NONE
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): HIGH

Do you need more information?

Contact Us