TYPO3 Modules Extension Improper Authentication Vulnerability

Vulnerability

A broken authentication vulnerability exists in the TYPO3 extension 'Modules' (codingms/modules), affecting versions prior to 4.3.11, 5.0.0 through 5.7.3, 6.0.0 through 6.4.1, and 7.0.0 through 7.5.4. The vulnerability allows authenticated backend users to log in as frontend users by bypassing access checks, particularly when the extension setting 'module.frontendUser.allowNonAdminUsersToLoginAsFrontendUser' is enabled.

Impact

Exploitation of this vulnerability allows for unauthorized login as a frontend user, potentially leading to unauthorized access to user-specific functionalities or data.

Remediation

Users are advised to update the 'Modules' extension to version 4.3.11, 5.7.4, 6.4.2, or 7.5.5, available through the TYPO3 extension manager, Packagist, or directly from the TYPO3 extensions repository.

Added: Nov 12, 2025, 12:18 PM
Updated: Nov 12, 2025, 4:30 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
6.2
remediation
7.7
relevance
1.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.