PT-2022-23196 · Typo3 · Typo3
Ingo Fabbri
·
Published
2022-09-13
·
Updated
2024-03-06
·
CVE-2022-36106
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
TYPO3 versions prior to 10.4.32
TYPO3 versions prior to 11.5.16
Description
The expiration time of a password reset link for TYPO3 backend users has never been evaluated, allowing a password reset link to be used even after the default expiry time of two hours has been exceeded.
Recommendations
Update to TYPO3 version 10.4.32 or later.
Update to TYPO3 version 11.5.16 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Typo3