Description
The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document placed in an indexed directory can cause local files to be read or outbound HTTP requests to be performed, with the retrieved content being written to the search index.
CVSS breakdown
CVSS 4.0
Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
High
User Interaction
None
Confidentiality (Vulnerable System)
High
Integrity (Vulnerable System)
None
Availability (Vulnerable System)
None
Confidentiality (Subsequent System)
Low
Integrity (Subsequent System)
None
Availability (Subsequent System)
None
Affected products
- TYPO3 / Extension "Faceted Search"7.0.0 – 7.0.1
- TYPO3 / Extension "Faceted Search"6.0.0 – 6.6.1
- TYPO3 / Extension "Faceted Search"5.0.0 – 5.6.2
- TYPO3 / Extension "Faceted Search"0 – 4.6.7