PT-2020-12524 · Typo3 · Typo3/Cms

Michael Kasten

·

Published

2020-05-13

·

Updated

2024-12-03

·

CVE-2020-11063

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions TYPO3 CMS versions 10.4.0 through 10.4.1
Description The issue allows an attacker to mount user enumeration based on email addresses assigned to backend user accounts using time-based attacks with the password reset functionality for backend users.
Recommendations For versions 10.4.0 through 10.4.1, update to version 10.4.2 to resolve the issue.

Exploit

Fix

Side Channel Attack

Weakness Enumeration

Related Identifiers

BIT-TYPO3-2020-11063
CVE-2020-11063
GHSA-347X-877P-HCWX

Affected Products

Typo3/Cms