← back
CVE-2022-23501

TYPO3 vulnerable to Improper Authentication in Frontend Login

CVSS 5.9 MEDIUMEPSS 0.5%CWE-287
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.9EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
14 Dec 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
TYPO3 is an open source PHP based web content management system. In versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 TYPO3 is vulnerable to Improper Authentication. Restricting frontend login to specific users, organized in different storage folders (partitions), can be bypassed. A potential attacker might use this ambiguity in usernames to get access to a different account - however, credentials must be known to the adversary. This issue is patched in versions 8.7.49 ELTS, 9.5.38 ELTS, 10.4.33, 11.5.20, 12.1.1.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
Affected products
TYPO3 · typo3

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →