Password Management Vulnerability in TYPO3 Web Content Management System
CVE-2025-47938
3.8LOW
What is CVE-2025-47938?
TYPO3, an open-source PHP-based web content management system, has a vulnerability in its backend user management interface. Versions prior to 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS allow administrators to change passwords without verifying their current passwords. This oversight could lead to unauthorized access if an admin session is hijacked or remains unattended. It is crucial for users to upgrade to the specified versions to mitigate this risk and enhance their system's security.
Affected Version(s)
typo3 >= 9.0.0, < 9.5.51 < 9.0.0, 9.5.51
typo3 >= 10.0.0, < 10.4.50 < 10.0.0, 10.4.50
typo3 >= 11.0.0, < 11.5.44 < 11.0.0, 11.5.44