GHSA-744g-7qm9-hjh9

Suggest an improvement
Source
https://github.com/advisories/GHSA-744g-7qm9-hjh9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-744g-7qm9-hjh9/GHSA-744g-7qm9-hjh9.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-744g-7qm9-hjh9
Aliases
Published
2025-05-20T19:39:37Z
Modified
2025-05-20T20:13:27.726359Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
The TYPO3 CMS Backend has Broken Authentication in Backend MFA
Details

Problem

The multifactor authentication (MFA) dialog presented during backend login can be bypassed due to insufficient enforcement of access restrictions on all backend routes.

Successful exploitation requires valid backend user credentials, as MFA can only be bypassed after successful authentication.

Solution

Update to TYPO3 versions 12.4.31 LTS, 13.4.12 LTS that fix the problem described.

Credits

Thanks to Jens Jacobsen and Y. Kahveci for reporting this issue, and to TYPO3 security team member Torben Hansen for fixing it.

Database specific
{
    "nvd_published_at": "2025-05-20T14:15:51Z",
    "cwe_ids": [
        "CWE-288"
    ],
    "github_reviewed_at": "2025-05-20T19:39:37Z",
    "severity": "HIGH",
    "github_reviewed": true
}
References

Affected packages

Packagist / typo3/cms-backend

Package

Name
typo3/cms-backend
Purl
pkg:composer/typo3/cms-backend

Affected ranges

Type
ECOSYSTEM
Events
Introduced
12.0.0
Fixed
12.4.31

Affected versions

v12.*

v12.0.0
v12.1.0
v12.1.1
v12.1.2
v12.1.3
v12.2.0
v12.3.0
v12.4.0
v12.4.1
v12.4.2
v12.4.3
v12.4.4
v12.4.5
v12.4.6
v12.4.7
v12.4.8
v12.4.9
v12.4.10
v12.4.11
v12.4.12
v12.4.13
v12.4.14
v12.4.15
v12.4.16
v12.4.17
v12.4.18
v12.4.19
v12.4.20
v12.4.21
v12.4.22
v12.4.23
v12.4.24
v12.4.25
v12.4.26
v12.4.27
v12.4.28
v12.4.29
v12.4.30

Database specific

last_known_affected_version_range

"<= 12.4.30"

source

"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-744g-7qm9-hjh9/GHSA-744g-7qm9-hjh9.json"

Packagist / typo3/cms-backend

Package

Name
typo3/cms-backend
Purl
pkg:composer/typo3/cms-backend

Affected ranges

Type
ECOSYSTEM
Events
Introduced
13.0.0
Fixed
13.4.12

Affected versions

v13.*

v13.0.0
v13.0.1
v13.1.0
v13.1.1
v13.2.1
v13.3.0
v13.3.1
v13.4.0
v13.4.1
v13.4.2
v13.4.3
v13.4.4
v13.4.5
v13.4.6
v13.4.7
v13.4.8
v13.4.9
v13.4.10
v13.4.11

Database specific

last_known_affected_version_range

"<= 13.4.11"

source

"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-744g-7qm9-hjh9/GHSA-744g-7qm9-hjh9.json"