VulnerabilityModified
CVE-2009-1264
Frontend User Registration (sr_feuser_register) extension 2.5.20 and earlier for TYPO3 does not properly verify access rights, which allows remote authenticated users to obtain sensitive information such as passwords via unknown attack vectors.
MEDIUM 4.0EPSS 1.15%
Does this matter?
Lower severity and a low EPSS score (1.15%). Track it; it rarely justifies an emergency change on its own.
Description
Frontend User Registration (sr_feuser_register) extension 2.5.20 and earlier for TYPO3 does not properly verify access rights, which allows remote authenticated users to obtain sensitive information such as passwords via unknown attack vectors.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
- EPSS
- 1.15% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- stanislas rolland/sr feuser register
- Source
- cve@mitre.org
References
- http://osvdb.org/53278
- http://secunia.com/advisories/34586Vendor Advisory
- http://typo3.org/extensions/repository/view/sr_feuser_register/2.5.21/Patch, Vendor Advisory
- http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-004/Patch, Vendor Advisory
- http://www.securityfocus.com/bid/34374Patch
- http://www.vupen.com/english/advisories/2009/0938Patch, Vendor Advisory
- http://osvdb.org/53278
- http://secunia.com/advisories/34586Vendor Advisory
- http://typo3.org/extensions/repository/view/sr_feuser_register/2.5.21/Patch, Vendor Advisory
- http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-004/Patch, Vendor Advisory
- http://www.securityfocus.com/bid/34374Patch
- http://www.vupen.com/english/advisories/2009/0938Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.