CVE-2020-26228
published 2020-11-23CVE-2020-26228: TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 user session identifiers were stored in cleartext…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.67%
47.2th percentile
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 user session identifiers were stored in cleartext - without processing with additional cryptographic hashing algorithms. This vulnerability cannot be exploited directly and occurs in combination with a chained attack - like for instance SQL injection in any other component of the system. Update to TYPO3 versions 9.5.23 or 10.4.10 that fix the problem described.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| typo3 | cms | >= 10.0.0 < 10.4.10 | 10.4.10 |
| typo3 | cms | >= 8.7.0 < 8.7.38 | 8.7.38 |
| typo3 | cms | >= 9.0.0 < 9.5.23 | 9.5.23 |
| typo3 | cms-core | >= 10.0.0 < 10.4.10 | 10.4.10 |
| typo3 | cms-core | >= 8.7.0 < 8.7.38 | 8.7.38 |
| typo3 | cms-core | >= 9.0.0 < 9.5.23 | 9.5.23 |
| typo3 | typo3 | >= 10.0.0 < 10.4.10 | 10.4.10 |
| typo3 | typo3 | >= 9.0.0 < 9.5.23 | 9.5.23 |
| typo3 | typo3.cms | — | — |
| typo3 | typo3.cms | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Cleartext storage of session identifier
ghsa·2020-11-23
CVE-2020-26228 [HIGH] CWE-312 Cleartext storage of session identifier
Cleartext storage of session identifier
User session identifiers were stored in cleartext - without processing of additional cryptographic hashing algorithms. This vulnerability cannot be exploited directly and occurs in combination with a chained attack - like for instance SQL injection in any other component of the system.
### Solution
Update to TYPO3 versions 9.5.23 or 10.4.10 that fix the problem described.
### Credits
Thanks to TYPO3 security team member Helmut Hummel who reported this issue and to TYPO3 core & security team members Benni Mack & Oliver Hader as well as TYPO3 contributor Markus Klein who fixed the issue.
OSV
Cleartext storage of session identifier
osv·2020-11-23
CVE-2020-26228 [HIGH] Cleartext storage of session identifier
Cleartext storage of session identifier
User session identifiers were stored in cleartext - without processing of additional cryptographic hashing algorithms. This vulnerability cannot be exploited directly and occurs in combination with a chained attack - like for instance SQL injection in any other component of the system.
### Solution
Update to TYPO3 versions 9.5.23 or 10.4.10 that fix the problem described.
### Credits
Thanks to TYPO3 security team member Helmut Hummel who reported this issue and to TYPO3 core & security team members Benni Mack & Oliver Hader as well as TYPO3 contributor Markus Klein who fixed the issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-11-23
Published