PT-2020-12524 · Typo3 · Typo3/Cms
Michael Kasten
·
Published
2020-05-13
·
Updated
2024-12-03
·
CVE-2020-11063
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
TYPO3 CMS versions 10.4.0 through 10.4.1
Description
The issue allows an attacker to mount user enumeration based on email addresses assigned to backend user accounts using time-based attacks with the password reset functionality for backend users.
Recommendations
For versions 10.4.0 through 10.4.1, update to version 10.4.2 to resolve the issue.
Exploit
Fix
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Typo3/Cms