Snyk has a published code exploit for this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade typo3/cms
to version 8.7.23, 9.5.4 or higher.
typo3/cms is a free open source Content Management Framework.
Affected versions of this package are vulnerable to Security Misconfiguration. When trying to change the type of an existing backend user, the backend form is reloaded in order to reflect changed configuration possibilities. This can lead to an account with empty credentials. This weakness cannot be directly exploited and requires interaction on purpose by some backend user having according privileges.