CVE-2019-11832
TYPO3 8.x before 8.7.25 and 9.x before 9.5.6 allows remote code execution because it does not properly configure the applications used for image processing, as demonstrated by ImageMagick or GraphicsMagick.
- Affected products
- Ghostscript, Graphicsmagick, Imagemagick, Typo3
- typo3
- < 8.7.25, 9.5.6
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 3.9% (89th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2019-05-09
CVE-2019-11832 at NVD
No indexed exploits for CVE-2019-11832 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2019-11832 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.