Storing Passwords in a Recoverable Format Affecting typo3/cms-backend package, versions <11.5.35>=12.0.0, <12.4.11>=13.0.0, <13.0.1


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Mature
EPSS
0.05% (20th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-TYPO3CMSBACKEND-6245715
  • published14 Feb 2024
  • disclosed13 Feb 2024
  • creditMaximilian Beckmann, Klaus-Günther Schmidt

Introduced: 13 Feb 2024

CVE-2024-25118  (opens in a new tab)
CWE-257  (opens in a new tab)

How to fix?

Upgrade typo3/cms-backend to version 11.5.35, 12.4.11, 13.0.1 or higher.

Overview

Affected versions of this package are vulnerable to Storing Passwords in a Recoverable Format in the form of reflection of password hashes in the editing forms of the backend user interface. An attacker can crack the plaintext password using brute force techniques by exploiting this vulnerability, which requires a valid backend user account.

CVSS Scores

version 3.1