CVE-2017-6370
MEDIUM 5.3EPSS 1.0%
TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields.
- CVSS v3.0
- 5.3 MEDIUM
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N - CVSS v3.0
- 5.3 MEDIUM
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N - CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N - EPSS
- 0.99% chance of exploitation in the next 30 days, 60th percentile
- Published
- 2017-03-17
- Updated
- 2024-08-05
Proof-of-concept exploits (1)
- faizzaidi/TYPO3-v7.6.15-Unencrypted-Login-Request2★ · 2017-03-20