TYPO3
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*
- >= 12.0.0, <= 12.4.30
- >= 13.0.0, <= 13.4.11
A vulnerability exists in TYPO3 versions 12.x prior to 12.4.31 LTS and 13.x prior to 13.4.2 LTS, allowing the multifactor authentication (MFA) dialog to be bypassed during backend login. This issue arises from inadequate enforcement of access restrictions on all backend routes. Exploitation of this vulnerability requires valid backend user credentials, as the MFA bypass can only occur after successful authentication.
Exploitation of this vulnerability allows for bypassing multifactor authentication in the backend, potentially leading to unauthorized access or actions by authenticated users.
Users are advised to update TYPO3 to versions 12.4.31 LTS or 13.4.12 LTS, which address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.