THREAT OPS › Threat News › [GHSA] GHSA-mfqj-cqv3-h7xw (medium) — TYPO3 CMS - Unrestricted File Upload in Form Framework
[GHSA] GHSA-mfqj-cqv3-h7xw (medium) — TYPO3 CMS - Unrestricted File Upload in Form Framework
GHSA-mfqj-cqv3-h7xw Severity: medium CVE: CVE-2026-15305
TYPO3 CMS - Unrestricted File Upload in Form Framework
### Problem Users were able to upload files with arbitrary MIME types to forms using _FileUpload_ or _ImageUpload_ elements with _allowedMimeTypes_ configured - uploading PHP files was **not** possible. The restriction was not enforced server-side because the _MimeTypeValidator_ was re
Indicators of compromise
- CVE-2026-15305cve
Original source: https://github.com/advisories/GHSA-mfqj-cqv3-h7xw