fal_sftp extension for TYPO3 uses weak permissions for sFTP driver files and folders
Moderate severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Apr 14, 2025
Description
Published by the National Vulnerability Database
Oct 27, 2014
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Apr 14, 2025
Last updated
Apr 14, 2025
The fal_sftp extension before 0.2.6 for TYPO3 uses weak permissions for sFTP driver files and folders, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
References