CVE-2014-3944Improper Authentication in CMS

Severity
5.8MEDIUMNVD
EPSS
0.2%
top 59.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 3
Latest updateMay 17

Description

The Authentication component in TYPO3 6.2.0 before 6.2.3 does not properly invalidate timed out user sessions, which allows remote attackers to bypass authentication via unspecified vectors.

CVSS vector

AV:N/AC:M/C:P/I:P/A:NExploitability: 8.6 | Impact: 4.9

Affected Packages2 packages

Packagisttypo3/cms6.2.06.2.3
NVDtypo3/typo34 versions+3

🔴Vulnerability Details

3
OSV
TYPO3 Improper Session Invalidation2022-05-17
GHSA
TYPO3 Improper Session Invalidation2022-05-17
CVEList
CVE-2014-3944: The Authentication component in TYPO3 62014-06-03
CVE-2014-3944 — Improper Authentication in Typo3 CMS | cvebase