TYPO3 CMS Install Tool Password Logging Vulnerability

Vulnerability

A vulnerability in TYPO3 CMS versions 13.4.2 has been identified, where the Install Tool password was logged in plaintext. This occurred if the password hashing mechanism was incorrect. Users are recommended to update to TYPO3 version 13.4.3 LTS, which addresses this issue. No workarounds are available.

Impact

This vulnerability leads to unauthorized information disclosure by logging passwords in plaintext.

Remediation

Users should update to TYPO3 version 13.4.3 LTS, which fixes this vulnerability. Instructions for downloading TYPO3 can be found on the official TYPO3 website.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
2.5
exploitability
5.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.