CVE-2020-15099 affects TYPO3 CMS versions >= 9.0.0 and < 9.5.20, and >= 10.0.0 and < 10.4.6. The issue allows arbitrary file retrieval from the TYPO3 installation if an attacker is able to generate a valid HMAC-SHA1 value for the targeted request or data structure. According to the advisory, this prerequisite may be met either through a separate vulnerability that enables valid HMAC generation or through prior disclosure of TYPO3's internal encryptionKey. Successful exploitation can expose sensitive local files, notably typo3conf/LocalConfiguration.php, which contains the TYPO3 encryptionKey and database connection credentials. The vulnerability is therefore an exposure of sensitive information to an unauthorized actor with downstream compromise potential.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, focused exploit project for TYPO3 CVE-2020-15099. It contains two files: a README with exploitation guidance and one Python entry-point script, typo3_exploit.py. The script is a real exploit, not a scanner or detection utility. The exploit targets unsafe deserialization in TYPO3 Form Framework frontend handling of the __state parameter. Its core capability is to forge a valid HMAC-signed serialized payload using a known TYPO3 encryptionKey, submit that payload to an unauthenticated frontend form, trigger a phpggc Guzzle/FW1 gadget chain, and write a PHP webshell to an attacker-chosen path under the web root. After delivery, it waits, verifies shell availability over HTTP, and can open an interactive command shell by sending commands through the shell's cmd GET parameter. Repository structure is simple: README.md documents prerequisites, vulnerable versions, required parameters, and operational workflow; typo3_exploit.py implements the attack flow. From the visible code and README, the script performs these stages: parse CLI arguments; normalize the target URL; create a local PHP shell file; fetch the target form page to obtain a fresh cHash and extract __trustedProperties; generate a serialized gadget payload using phpggc with PHP 7.2 compatibility (Docker by default, local PHP optional); sign the payload with HMAC-SHA1 using the leaked encryptionKey; POST the payload in the TYPO3 form field tx_form_formframework[<form>][__state]; wait for the gadget destructor to write the shell; verify the shell URL; and optionally provide an interactive shell session. The exploit is network-based and operationally mature enough to automate end-to-end exploitation, but it uses a basic hardcoded payload (a simple PHP webshell), so OPERATIONAL is the best fit rather than WEAPONIZED. Fingerprintable targets and artifacts include TYPO3 configuration file paths used to obtain the encryptionKey, common writable TYPO3 directories for shell placement, the shell URL, the form page URL pattern, and the specific TYPO3 form parameter name used for exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.