PT-2022-23196 · Typo3 · Typo3

Ingo Fabbri

·

Published

2022-09-13

·

Updated

2024-03-06

·

CVE-2022-36106

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions TYPO3 versions prior to 10.4.32 TYPO3 versions prior to 11.5.16
Description The expiration time of a password reset link for TYPO3 backend users has never been evaluated, allowing a password reset link to be used even after the default expiry time of two hours has been exceeded.
Recommendations Update to TYPO3 version 10.4.32 or later. Update to TYPO3 version 11.5.16 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-TYPO3-2022-36106
CVE-2022-36106
GHSA-5959-4X58-R8C2

Affected Products

Typo3