Get a Pentest and security assessment of your IT network.

2021-current

CVE-2020-26228 – TYPO3 is an open source PHP based web content management system. In TYPO3

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 user session identifiers were stored in cleartext – without processing with additional cryptographic hashing algorithms. This vulnerability cannot be exploited directly and occurs in combination with a chained attack – like for instance SQL injection in any other component of the system. Update to TYPO3 versions 9.5.23 or 10.4.10 that fix the problem described.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26228

Reference (s):

  • https://github.com/TYPO3/TYPO3.CMS/security/advisories/GHSA-954j-f27r-cj52
  • URL: https://github.com/TYPO3/TYPO3.CMS/security/advisories/GHSA-954j-f27r-cj52
  • https://typo3.org/security/advisory/typo3-core-sa-2020-011
  • URL: https://typo3.org/security/advisory/typo3-core-sa-2020-011
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2014-6594 - Unspecified vulnerability in the Oracle iLearning component in Oracle iLe

2021-current

CVE-2019-8457 - SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-b

2021-current

CVE-2020-12257 - rConfig 3.9.4 is vulnerable to cross-site request forgery (CSRF) because