PT-2025-3142 · Typo3 · Typo3
Oliver Hader
·
Published
2025-01-14
·
Updated
2025-01-15
·
CVE-2024-55891
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
TYPO3 versions prior to 13.4.3 ELTS
Description
A problem has been discovered where the install tool password is logged as plaintext if the password hashing mechanism used for the password was incorrect. There are no known workarounds for this issue. Users are advised to update to a fixed version.
Recommendations
Update to TYPO3 version 13.4.3 ELTS, which fixes the problem described. As a temporary workaround, consider restricting access to the install tool until the update is applied.
Exploit
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Typo3