Remote Information Disclosure in TYPO3 Dynamic Content Elements Extension
CVE-2014-8328
5.3MEDIUM
Key Information:
- Status
- Vendor
- CVE Published:
- 3 February 2020
What is CVE-2014-8328?
The Dynamic Content Elements (dce) extension for TYPO3 prior to version 0.11.5 has a default configuration that exposes sensitive installation environment information. This vulnerability enables remote attackers to gain access to crucial details by intercepting the update check request. The flaw underscores the importance of configuring extensions securely to mitigate risks associated with unauthorized data access.
