PT-2022-16034 · Typo3 · Typo3

Torben Hansen

·

Published

2022-12-13

·

Updated

2024-03-06

·

CVE-2022-23501

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions TYPO3 versions prior to 8.7.49 TYPO3 versions prior to 9.5.38 TYPO3 versions prior to 10.4.33 TYPO3 versions prior to 11.5.20 TYPO3 versions prior to 12.1.1
Description The issue concerns Improper Authentication in TYPO3, an open source PHP based web content management system. Restricting frontend login to specific users, organized in different storage folders (partitions), can be bypassed. A potential attacker might use this ambiguity in usernames to get access to a different account, however, credentials must be known to the adversary.
Recommendations Update to TYPO3 version 8.7.49 ELTS to fix the issue. Update to TYPO3 version 9.5.38 ELTS to fix the issue. Update to TYPO3 version 10.4.33 to fix the issue. Update to TYPO3 version 11.5.20 to fix the issue. Update to TYPO3 version 12.1.1 to fix the issue.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

BIT-TYPO3-2022-23501
CVE-2022-23501
GHSA-JFP7-79G7-89RF

Affected Products

Typo3