cbcvebase.
CVE-2021-21339
published 2021-03-23

CVE-2021-21339: TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 user session…

PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.92%
55.7th percentile
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 user session identifiers were stored in cleartext - without processing of additional cryptographic hashing algorithms. This vulnerability cannot be exploited directly and occurs in combination with a chained attack - like for instance SQL injection in any other component of the system. This is fixed in versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1.

Affected

21 ranges
VendorProductVersion rangeFixed in
typo3cms>= 10.0.0 < 10.4.1410.4.14
typo3cms>= 11.0.0 < 11.1.111.1.1
typo3cms>= 9.0.0 < 9.5.259.5.25
typo3cms-core>= 10.0.0 < 10.4.1410.4.14
typo3cms-core>= 11.0.0 < 11.1.111.1.1
typo3cms-core>= 6.2.0 < 6.2.576.2.57
typo3cms-core>= 7.0.0 < 7.6.517.6.51
typo3cms-core>= 8.0.0 < 8.7.408.7.40
typo3cms-core>= 9.0.0 < 9.5.259.5.25
typo3typo3>= 10.0.0 < 10.4.1410.4.14
typo3typo3>= 11.0.0 < 11.1.111.1.1
typo3typo3>= 6.2.0 < 6.2.576.2.57
typo3typo3>= 7.0.0 < 7.6.517.6.51
typo3typo3>= 8.0.0 < 8.7.408.7.40
typo3typo3>= 9.0.0 < 9.5.259.5.25
typo3typo3.cms
typo3typo3.cms
typo3typo3.cms
typo3typo3.cms
typo3typo3.cms
typo3typo3.cms

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.