PT-2025-3142 · Typo3 · Typo3

Oliver Hader

·

Published

2025-01-14

·

Updated

2025-01-15

·

CVE-2024-55891

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions TYPO3 versions prior to 13.4.3 ELTS
Description A problem has been discovered where the install tool password is logged as plaintext if the password hashing mechanism used for the password was incorrect. There are no known workarounds for this issue. Users are advised to update to a fixed version.
Recommendations Update to TYPO3 version 13.4.3 ELTS, which fixes the problem described. As a temporary workaround, consider restricting access to the install tool until the update is applied.

Exploit

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2024-55891
GHSA-38X7-CC6W-J27Q

Affected Products

Typo3