Lucene search

K
githubGitHub Advisory DatabaseGHSA-JQR8-Q455-XX45
HistoryMay 30, 2024 - 9:12 p.m.

TYPO3 Brute Force Protection Bypass in backend login

2024-05-3021:12:16
CWE-20
GitHub Advisory Database
github.com
10
typo3
brute force
backend login
protection bypass
special request

AI Score

7.1

Confidence

High

The backend login has a basic brute force protection implementation which pauses for 5 seconds if wrong credentials are given. This pause however could be bypassed by forging a special request, making brute force attacks on backend editor credentials more feasible.

Affected configurations

Vulners
Node
typo3typo3_cmsRange7.0.07.3.1
OR
typo3typo3_cmsRange6.2.06.2.14
VendorProductVersionCPE
typo3typo3_cms*cpe:2.3:a:typo3:typo3_cms:*:*:*:*:*:*:*:*

AI Score

7.1

Confidence

High