THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-mfqj-cqv3-h7xw (medium) — TYPO3 CMS - Unrestricted File Upload in Form Framework

[GHSA] GHSA-mfqj-cqv3-h7xw (medium) — TYPO3 CMS - Unrestricted File Upload in Form Framework

medgithub_advisoriesPublished 2026-08-31

GHSA-mfqj-cqv3-h7xw Severity: medium CVE: CVE-2026-15305

TYPO3 CMS - Unrestricted File Upload in Form Framework

### Problem Users were able to upload files with arbitrary MIME types to forms using _FileUpload_ or _ImageUpload_ elements with _allowedMimeTypes_ configured - uploading PHP files was **not** possible. The restriction was not enforced server-side because the _MimeTypeValidator_ was re

Indicators of compromise

Original source: https://github.com/advisories/GHSA-mfqj-cqv3-h7xw