First published: Tue Apr 07 2009(Updated: )
Frontend User Registration (sr_feuser_register) extension 2.5.20 and earlier for TYPO3 does not properly verify access rights, which allows remote authenticated users to obtain sensitive information such as passwords via unknown attack vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TYPO3 | ||
TYPO3 sr_feuser_register | <=2.5.20 | |
TYPO3 sr_feuser_register | =1.4 | |
TYPO3 sr_feuser_register | =1.6 | |
TYPO3 sr_feuser_register | =2.2.1 | |
TYPO3 sr_feuser_register | =2.2.7 | |
TYPO3 sr_feuser_register | =2.2.8 | |
TYPO3 sr_feuser_register | =2.3 | |
TYPO3 sr_feuser_register | =2.3.6 | |
TYPO3 sr_feuser_register | =2.4 | |
TYPO3 sr_feuser_register | =2.5 | |
TYPO3 sr_feuser_register | =2.5.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1264 has a medium severity rating due to its potential to expose sensitive user information.
To fix CVE-2009-1264, upgrade the TYPO3 Frontend User Registration extension to version 2.5.21 or later.
CVE-2009-1264 affects all versions of the TYPO3 Frontend User Registration extension from 2.5.20 and earlier.
CVE-2009-1264 allows attackers to obtain sensitive information such as passwords from the affected TYPO3 installation.
Yes, CVE-2009-1264 can be exploited by remote authenticated users.