Description
The Color Picker Wizard component in TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, and 6.1.0 before 6.1.9 allows remote authenticated editors to execute arbitrary PHP code via a serialized PHP object.
Remediation
References
Related Vulnerabilities
Contao Improper Input Validation Vulnerability (CVE-2020-25768)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-3092)
Moodle Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2020-1754)
Apache 2.x version older than 2.2.8
WordPress Plugin Share, Print and PDF Products for WooCommerce Security Bypass (2.7.2)