CVE-2020-28917

MEDIUM

view_frontend_statistics < 2.0.1 - Cleartext Storage of Sensitive Information in Database

Title source: llm
STIX 2.1

Description

An issue was discovered in the view_statistics (aka View frontend statistics) extension before 2.0.1 for TYPO3. It saves all GET and POST data of TYPO3 frontend requests to the database. Depending on the extensions used on a TYPO3 website, sensitive data (e.g., cleartext passwords if ext:felogin is installed) may be saved.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0052
EPSS Percentile 40.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-312
Status published
Products (1)
view_frontend_statistics_project/view_frontend_statistics < 2.0.1
Published Nov 18, 2020
Tracked Since Feb 18, 2026