Insufficient Entropy in Password Generation
CVE-2025-59015
6.3MEDIUM
What is CVE-2025-59015?
A deterministic three‑character prefix in the Password Generation component of TYPO3 CMS versions 12.0.0–12.4.36 and 13.0.0–13.4.17 reduces entropy, allowing attackers to carry out brute‑force attacks more quickly.
Affected Version(s)
TYPO3 CMS 12.0.0 < 12.4.37
TYPO3 CMS 13.0.0 < 13.4.18