CVE-2009-0256
Session fixation vulnerability in the authentication library in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote attackers to hijack web sessions via unspecified vectors related to (1) frontend and (2) backend…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.79%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Session fixation vulnerability in the authentication library in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote attackers to hijack web sessions via unspecified vectors related to (1) frontend and (2) backend authentication.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.79% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- typo3/typo3
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/33617Vendor Advisory
- http://secunia.com/advisories/33679
- http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-001/Vendor Advisory
- http://www.debian.org/security/2009/dsa-1711
- http://www.securityfocus.com/bid/33376
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48133
- http://secunia.com/advisories/33617Vendor Advisory
- http://secunia.com/advisories/33679
- http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-001/Vendor Advisory
- http://www.debian.org/security/2009/dsa-1711
- http://www.securityfocus.com/bid/33376
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48133
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.