← Vulnerability feed

Vulnerability record · CVE-2009-0815 · published 5 March 2009

CVE-2009-0815: Typo3 information exposure vulnerability

Typo3 · Typo3

The jumpUrl mechanism in class.tslib_fe.php in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 leaks a hash secret (juHash) in an error message, which allows remote attackers to read arbitrary files by including the hash in a request.

5.0 CVSS 2.0 Medium EPSS 42% · top 1.3% CWE-200 · Information exposure
5.0CVSS 2.0 base score
42%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

The jumpUrl mechanism in class.tslib_fe.php in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 leaks a hash secret (juHash) in an error message, which allows remote attackers to read arbitrary files by including the hash in a request.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-0815 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-11066Typo3 mass assignment vulnerabilityIn TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, calling unserialize() on m…EPSS 1.5%10.0CVE-2009-0258Typo3 improper input validation vulnerabilityThe Indexed Search Engine (indexed_search) system extension in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote …EPSS 3.3%9.8CVE-2011-3583Typo3 sql injection vulnerabilityIt was found that Typo3 Core versions 4.5.0 - 4.5.5 uses prepared statements that, if the parameter values are not properly replaced, could lead to a…EPSS 1.4%9.8CVE-2011-4628Typo3 improper authentication vulnerabilityTYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to bypass authentication mechanisms in the backend through a …EPSS 1.6%8.8CVE-2024-55921Typo3 cross-site request forgery vulnerabilityTYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involvi…EPSS 0.36%8.8CVE-2022-23503Typo3 code injection vulnerabilityTYPO3 is an open source PHP based web content management system. Versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 are vulnerable to Cod…EPSS 0.81%8.8CVE-2021-41113Typo3 cross-site request forgery vulnerabilityTYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the new TYPO3 v11 feature tha…EPSS 0.64%8.8CVE-2020-15098Typo3 improper input validation vulnerabilityIn TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, it has been discovered th…EPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2009-0815), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.