PT-2022-28056 · Typo3 · Fe Change Pwd

Torben Hansen

·

Published

2022-12-14

·

Updated

2025-04-21

·

CVE-2022-47406

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions fe change pwd extension versions 2.0.5 and earlier, 3.x versions prior to 3.0.3
Description An issue was discovered in the fe change pwd extension for TYPO3, where the extension fails to revoke existing sessions for the current user when the password has been changed.
Recommendations For fe change pwd extension versions 2.0.5 and earlier, update to version 2.0.5 or later. For fe change pwd extension 3.x versions prior to 3.0.3, update to version 3.0.3 or later.

Exploit

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

CVE-2022-47406
GHSA-53MM-HX32-6475

Affected Products

Fe Change Pwd