CVE-2013-4250
Estado: ModificadaMedia (6.5)—
The (1) file upload component and (2) File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.3 do not properly check file extensions, which allow remote authenticated editors to execute arbitrary PHP code by uploading a .php file.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.15%
- Percentil entre todas las CVEs puntuadas: 66
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-20
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2013-4250",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2014-05-20T14:55:04.147",
"references": [
{
"url": "https://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2013-002/",
"tags": [
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2013-002/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The (1) file upload component and (2) File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.3 do not properly check file extensions, which allow remote authenticated editors to execute arbitrary PHP code by uploading a .php file."
},
{
"lang": "es",
"value": "El (1) componente de carga de archivos y (2) la Capa de Abstracción de Archivo (FAL) en TYPO3 versiones 6.0.x anteriores a 6.0.8 y versiones 6.1.x anteriores a 6.1.3, no comprueba apropiadamente las extensiones de archivo, que le permiten a editores autenticados remotos ejecutar código PHP arbitrario mediante la carga de un archivo .php."
}
],
"lastModified": "2026-06-16T23:56:53.697",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:typo3:typo3:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "84C095F8-000A-4A8D-81DE-047810345A15"
},
{
"criteria": "cpe:2.3:a:typo3:typo3:6.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "976AAF6F-BF03-40B7-B7D2-22101BD857D7"
},
{
"criteria": "cpe:2.3:a:typo3:typo3:6.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6E98D0D9-D9AE-44F7-8233-F92EB330B152"
},
{
"criteria": "cpe:2.3:a:typo3:typo3:6.0.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "36EA784A-7C3A-41DA-B444-D01E3BC144BB"
},
{
"criteria": "cpe:2.3:a:typo3:typo3:6.0.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7294AA8B-0CD3-47A2-91DC-A882F7F3BDFC"
},
{
"criteria": "cpe:2.3:a:typo3:typo3:6.0.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D28DD85-FBB3-4DD4-B525-7AFD32BE55F6"
},
{
"criteria": "cpe:2.3:a:typo3:typo3:6.0.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "80C21E07-5083-4C86-AA9D-FCB73F636060"
},
{
"criteria": "cpe:2.3:a:typo3:typo3:6.0.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5DAE1BB4-2DBD-489E-B3F9-88CF414EAC2C"
},
{
"criteria": "cpe:2.3:a:typo3:typo3:6.0.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A862C28E-B1B9-4541-A559-D0BD16E575B4"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:typo3:typo3:6.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C140F242-CF7C-4CB6-A358-5C8DB0F26DAA"
},
{
"criteria": "cpe:2.3:a:typo3:typo3:6.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "81EAC0BA-B6AC-42BA-AEEE-946E1FBD770B"
},
{
"criteria": "cpe:2.3:a:typo3:typo3:6.1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AD31180A-8BD6-49AC-A758-5FA4C9A7B4C8"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}