Password Management Vulnerability in TYPO3 Web Content Management System
CVE-2025-47938

3.8LOW

Key Information:

Vendor

Typo3

Status
Vendor
CVE Published:
20 May 2025

What is CVE-2025-47938?

TYPO3, an open-source PHP-based web content management system, has a vulnerability in its backend user management interface. Versions prior to 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS allow administrators to change passwords without verifying their current passwords. This oversight could lead to unauthorized access if an admin session is hijacked or remains unattended. It is crucial for users to upgrade to the specified versions to mitigate this risk and enhance their system's security.

Affected Version(s)

typo3 >= 9.0.0, < 9.5.51 < 9.0.0, 9.5.51

typo3 >= 10.0.0, < 10.4.50 < 10.0.0, 10.4.50

typo3 >= 11.0.0, < 11.5.44 < 11.0.0, 11.5.44

References

CVSS V3.1

Score:
3.8
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-47938 : Password Management Vulnerability in TYPO3 Web Content Management System