← back
CVE-2024-55891

Information Disclosure via Exception Handling/Logger in TYPO3

CVSS 3.1 LOWEPSS 0.3%CWE-532
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 3.1EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
14 Jan 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
TYPO3 is a free and open source Content Management Framework. It has been discovered that the install tool password has been logged as plaintext in case the password hashing mechanism used for the password was incorrect. Users are advised to update to TYPO3 versions 13.4.3 ELTS which fixes the problem described. There are no known workarounds for this vulnerability.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products
TYPO3 · typo3

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →