CVE-2009-3635

Typo3 < 4.0.12 - Authentication Bypass

Title source: rule

Description

The Install Tool subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attackers to gain access by using only the password's md5 hash as a credential.

Scores

EPSS 0.0104
EPSS Percentile 77.2%

Classification

CWE
CWE-287
Status draft

Affected Products (50)

typo3/typo3 < 4.0.12
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
... and 35 more

Timeline

Published Nov 02, 2009
Tracked Since Feb 18, 2026