Plaintext Password Exposure in TYPO3 Content Management Framework
CVE-2024-55891
3.1LOW
What is CVE-2024-55891?
The TYPO3 Content Management Framework suffers from a security vulnerability where the install tool password can be inadvertently logged in plaintext due to an incorrect password hashing implementation. This exposes sensitive information and can potentially lead to unauthorized access. Users are strongly advised to upgrade to TYPO3 version 13.4.3 ELTS to mitigate this risk. Currently, there are no known workarounds for this vulnerability.
Affected Version(s)
typo3 < 13.4.3