Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database table. This issue affects TYPO3 CMS version 14.2.0.
oryginał ENCVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XTypo3
APPTypo314.2.0
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
CWE
Powiązane podatności
CVE-2011-3583CRITICAL9.8PL ✓ten sam produkt
SQL Injection w TYPO3 Core przez niepoprawne prepared statements
CVE-2011-4628CRITICAL9.8PL ✓ten sam produkt
TYPO3: Ominięcie mechanizmu uwierzytelniania w panelu administracyjnym
CVE-2025-59022HIGH7.1ten sam produkt
Backend users who had access to the recycler module could delete arbitrary data from any database table define...
CVE-2025-59018HIGH7.1ten sam produkt
Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0....
CVE-2025-47941HIGH7.2ten sam produkt
TYPO3 is an open source, PHP based web content management system. In versions on the 12.x branch prior to 12.4...