QID 997232

Date Published: 2024-02-15

QID 997232: PHP (Composer) Security Update for typo3/cms-core (GHSA-38r2-5695-334w)

Password hashes were being reflected in the editing forms of the TYPO3 backend user interface. This allowed attackers to crack the plaintext password using brute force techniques. Exploiting this vulnerability requires a valid backend user account.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-38r2-5695-334w for updates and patch information.
    Vendor References

    CVEs related to QID 997232

    Software Advisories
    Advisory ID Software Component Link
    GHSA-38r2-5695-334w typo3/cms-core URL Logo github.com/advisories/GHSA-38r2-5695-334w