Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-26228— Cleartext storage of session identifier

CVSS 8.1 · High EPSS 0.18% · P39
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2020-26228

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cleartext storage of session identifier
Source: NVD (National Vulnerability Database)
Vulnerability Description
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 user session identifiers were stored in cleartext - without processing with additional cryptographic hashing algorithms. This vulnerability cannot be exploited directly and occurs in combination with a chained attack - like for instance SQL injection in any other component of the system. Update to TYPO3 versions 9.5.23 or 10.4.10 that fix the problem described.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
敏感数据的明文存储
Source: NVD (National Vulnerability Database)
Vulnerability Title
TYPO3 加密问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
TYPO3是瑞士TYPO3(Typo3)协会的一套免费开源的内容管理系统(框架)(CMS/CMF)。 Typo3 存在加密问题漏洞,该漏洞源于将用户会话标识符以明文存储。该漏洞可以与其他问题结合利用,以检索会话标识符并获得对应用程序的未经授权的访问。攻击者可利用该漏洞攻击者访问敏感信息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
TYPO3TYPO3.CMS >= 9.0.0, < 9.5.23 -

II. Public POCs for CVE-2020-26228

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-26228

登录查看更多情报信息。

Same Patch Batch · TYPO3 · 2020-11-23 · 3 CVEs total

CVE-2020-262276.1 MEDIUMCross-Site Scripting in Fluid view helpers
CVE-2020-262293.7 LOWXML External Entity in Dashboard Widget

IV. Related Vulnerabilities

V. Comments for CVE-2020-26228

No comments yet


Leave a comment