CVE-2014-3945

Published Jun 3, 2014

Last updated 3 months ago

Overview

Description
The Authentication component in TYPO3 before 6.2, when salting for password hashing is disabled, does not require knowledge of the cleartext password if the password hash is known, which allows remote attackers to bypass authentication and gain access to the backend by leveraging knowledge of a password hash.
Source
cve@mitre.org
NVD status
Modified

Risk scores

CVSS 2.0

Type
Primary
Base score
4
Impact score
4.9
Exploitability score
4.9
Vector string
AV:N/AC:H/Au:N/C:P/I:P/A:N

Weaknesses

nvd@nist.gov
CWE-287

Social media

Hype score
Not currently trending

Configurations