CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2011-4628

CVSS 9.8v3.1pub. 2019-11-06upd. 2024-11-21

TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to bypass authentication mechanisms in the backend through a crafted request.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Typo3

    APP
    Typo3
    4.3.0 – 4.3.12 (excl.)4.4.0 – 4.4.9 (excl.)4.5.0 – 4.5.4 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2011-3583CRITICAL9.8PL ✓same product

SQL Injection w TYPO3 Core przez niepoprawne prepared statements

CVE-2026-6553HIGH7.3same product

Changing backend users' passwords via the user settings module results in storing the cleartext password in th...

CVE-2025-59022HIGH7.1same product

Backend users who had access to the recycler module could delete arbitrary data from any database table define...

CVE-2025-59018HIGH7.1same product

Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0....

CVE-2025-47940HIGH7.2same product

TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to vers...