TYPO3 CMS
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*
- >= 12.0.0, <= 12.4.36
- >= 13.0.0, <= 13.4.17
A vulnerability exists in the Password Generation component of TYPO3 CMS, specifically in versions 12.0.0 through 12.4.36 and 13.0.0 through 13.4.17. The issue arises from a deterministic three-character prefix that reduces the randomness of generated passwords, enabling attackers to conduct brute-force attacks more efficiently. This vulnerability is not present when the 'random' password rules are used.
Exploitation of this vulnerability allows for more efficient brute-force attacks on password-protected areas, potentially leading to unauthorized access.
Users are advised to update TYPO3 to versions 12.4.37 LTS or 13.4.18 LTS, which address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.