cvedb.io
CVE-2022-36104
MEDIUM · CVSS 5.9
EPSS exploitation probability: 0%
Published 2022-09-13T18:15:14.703 · Last modified 2026-06-17T04:52:55.787

Summary

TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions requesting invalid or non-existing resources via HTTP triggers the page error handler which again could retrieve content to be shown as an error message from another page. This leads to a scenario in which the application is calling itself recursively - amplifying the impact of the initial attack until the limits of the web server are exceeded. Users are advised to update to TYPO3 version 11.5.16 to resolve this issue. There are no known workarounds for this issue.

Affected products

typo3 — typo3

Does this affect you?

Add your gear to cvedb and we'll alert you only when typo3 ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.