CVE-2021-21339

MEDIUM

TYPO3 < 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 - Cleartext Session Identifiers

Title source: llm
STIX 2.1

Description

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 user session identifiers were stored in cleartext - without processing of additional cryptographic hashing algorithms. This vulnerability cannot be exploited directly and occurs in combination with a chained attack - like for instance SQL injection in any other component of the system. This is fixed in versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1.

References (3)

Core 3
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://packagist.org/packages/typo3/cms-core

Scores

CVSS v3 5.9
EPSS 0.0013
EPSS Percentile 32.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-312
Status published
Products (3)
typo3/cms 10.0.0 - 10.4.14Packagist
typo3/cms-core 6.2.0 - 6.2.57Packagist
typo3/typo3 6.2.0 - 6.2.57
Published Mar 23, 2021
Tracked Since Feb 18, 2026