<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 17:21:18 +0000</lastBuildDate>
    <item>
      <title>cnvd-2021-26141</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-26141</link>
      <description>cnvd-2021-26141</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-26141</guid>
    </item>
    <item>
      <title>EUVD-2026-22140</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-22140</link>
      <description>EUVD-2026-22140</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-22140</guid>
    </item>
    <item>
      <title>fkie_cve-2021-21355</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-21355</link>
      <description>&lt;p&gt;TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1, due to the lack of ensuring file extensions belong to configured allowed mime-types, attackers can upload arbitrary data with arbitrary file extensions - however, default _fileDenyPattern_ successfully blocked files like _.htaccess_ or _malicious.php_. Besides that, _UploadedFileReferenceConverter_ transforming uploaded files into proper FileReference domain model objects handles possible file uploads for other extensions as well - given those extensions use the Extbase MVC framework, make use of FileReference items in their direct or inherited domain model definitions and did not implement their own type converter. In case this scenario applies, _UploadedFileReferenceConverter_ accepts any file mime-type and persists files in the default location. In any way, uploaded files are placed in the default location _/fileadmin/user_upload/_, in most scenarios keeping the submitted filename - which allows attackers to directly reference files, or even correctly guess filenames used by other individuals, disclosing this information. No authentication is required to exploit this vulnerability. This is fixed in versions 8.7.40, 9.5.25, 10.4.14, 11.1.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1, due to the lack of ensuring file extensions belong to configured allowed mime-types, attackers can upload arbitrary data with arbitrary file extensions - however, default _fileDenyPattern_ successfully blocked files like _.htaccess_ or _malicious.php_. Besides that, _UploadedFileReferenceConverter_ transforming uploaded files into proper FileReference domain model objects handles possible file uploads for other extensions as well - given those extensions use the Extbase MVC framework, make use of FileReference items in their direct or inherited domain model definitions and did not implement their own type converter. In case this scenario applies, _UploadedFileReferenceConverter_ accepts any file mime-type and persists files in the default location. In any way, uploaded files are placed in the default location _/fileadmin/user_upload/_, in most scenarios keeping the submitted filename - which allows attackers to directly reference files, or even correctly guess filenames used by other individuals, disclosing this information. No authentication is required to exploit this vulnerability. This is fixed in versions 8.7.40, 9.5.25, 10.4.14, 11.1.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-21355</guid>
    </item>
    <item>
      <title>GHSA-2r6j-862c-m2v2 — Unrestricted File Upload in Form Framework</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2r6j-862c-m2v2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: typo3/cms-form, Packagist: typo3/cms-core, Packagist: typo3/cms&lt;/p&gt;
&lt;p&gt;### Problem
Due to the lack of ensuring file extensions belong to configured allowed mime-types, attackers can upload arbitrary data with arbitrary file extensions - however, default _fileDenyPattern_ successfully blocked files like _.htaccess_ or _malicious.php_.&lt;/p&gt;
&lt;p&gt;TYPO3 Extbase extensions, which implement a file upload and do not implement a custom _TypeConverter_ to transform uploaded files into _FileReference_ domain model objects are affected by the vulnerability as well, since the _UploadedFileReferenceConverter_ of _ext:form_ handles the file upload and will accept files of any mime-type which are persisted to the default location.&lt;/p&gt;
&lt;p&gt;In any way, uploaded files are placed in the default location _/fileadmin/user_upload/_, in most scenarios keeping the submitted filename - which allows attackers to directly reference files, or even correctly guess filenames used by other individuals, disclosing this information.&lt;/p&gt;
&lt;p&gt;No authentication is required to exploit this vulnerability.&lt;/p&gt;
&lt;p&gt;### Solution
Update to TYPO3 versions 8.7.40, 9.5.25, 10.4.14, 11.1.1 that fix the problem described.&lt;/p&gt;
&lt;p&gt;Type converter _UploadedFileReferenceConverter_ is not registered globally anymore and just handles uploaded files within the scope of the Form Framework. Guessable storage location has changed from _/fileadmin/user_upload/form\_\&amp;lt;random-hash\&amp;gt;/_ to _/fileadmin/form_uploads/&amp;lt;random-40-bit&amp;gt;_. Allowed mime-types must match expected file extensions (e.g. _application/pdf_ must be _.pdf_, and cannot be _.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: typo3/cms-form, Packagist: typo3/cms-core, Packagist: typo3/cms&lt;/p&gt;
&lt;p&gt;### Problem
Due to the lack of ensuring file extensions belong to configured allowed mime-types, attackers can upload arbitrary data with arbitrary file extensions - however, default _fileDenyPattern_ successfully blocked files like _.htaccess_ or _malicious.php_.&lt;/p&gt;
&lt;p&gt;TYPO3 Extbase extensions, which implement a file upload and do not implement a custom _TypeConverter_ to transform uploaded files into _FileReference_ domain model objects are affected by the vulnerability as well, since the _UploadedFileReferenceConverter_ of _ext:form_ handles the file upload and will accept files of any mime-type which are persisted to the default location.&lt;/p&gt;
&lt;p&gt;In any way, uploaded files are placed in the default location _/fileadmin/user_upload/_, in most scenarios keeping the submitted filename - which allows attackers to directly reference files, or even correctly guess filenames used by other individuals, disclosing this information.&lt;/p&gt;
&lt;p&gt;No authentication is required to exploit this vulnerability.&lt;/p&gt;
&lt;p&gt;### Solution
Update to TYPO3 versions 8.7.40, 9.5.25, 10.4.14, 11.1.1 that fix the problem described.&lt;/p&gt;
&lt;p&gt;Type converter _UploadedFileReferenceConverter_ is not registered globally anymore and just handles uploaded files within the scope of the Form Framework. Guessable storage location has changed from _/fileadmin/user_upload/form\_\&amp;lt;random-hash\&amp;gt;/_ to _/fileadmin/form_uploads/&amp;lt;random-40-bit&amp;gt;_. Allowed mime-types must match expected file extensions (e.g. _application/pdf_ must be _.pdf_, and cannot be _.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2r6j-862c-m2v2</guid>
    </item>
    <item>
      <title>gsd-2021-21355</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-21355</link>
      <description>gsd-2021-21355</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-21355</guid>
    </item>
  </channel>
</rss>
