Password Management Vulnerability in TYPO3 Web Content Management System
CVE-2025-47938
What is CVE-2025-47938?
TYPO3, an open-source PHP-based web content management system, has a vulnerability in its backend user management interface. Versions prior to 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS allow administrators to change passwords without verifying their current passwords. This oversight could lead to unauthorized access if an admin session is hijacked or remains unattended. It is crucial for users to upgrade to the specified versions to mitigate this risk and enhance their system's security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
typo3 >= 9.0.0, < 9.5.51 < 9.0.0, 9.5.51
typo3 >= 10.0.0, < 10.4.50 < 10.0.0, 10.4.50
typo3 >= 11.0.0, < 11.5.44 < 11.0.0, 11.5.44
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
