CVE-2009-1264: Medium severity typo3 vulnerability
Published Apr 7, 2009
·Updated
Frontend User Registration (srfeuserregister) extension 2.5.20 and earlier for TYPO3 does not properly verify access rights, which allows remote authenticated users to obtain sensitive information such as passwords via unknown attack vectors.
Affected Software
25 affected componentsFixes available
Typo3 TYPO3
Stanislas Rolland Sr Feuser Register<=2.5.20
Stanislas Rolland Sr Feuser Register=1.4
Stanislas Rolland Sr Feuser Register=1.6
Stanislas Rolland Sr Feuser Register=2.2.1
Stanislas Rolland Sr Feuser Register=2.2.7
Stanislas Rolland Sr Feuser Register=2.2.8
Stanislas Rolland Sr Feuser Register=2.3
Stanislas Rolland Sr Feuser Register=2.3.6
Stanislas Rolland Sr Feuser Register=2.4
Stanislas Rolland Sr Feuser Register=2.5
Stanislas Rolland Sr Feuser Register=2.5.10
composer/sjbr/sr-feuser-register<2.5.21
2.5.21
All of the following
Typo3 TYPO3
Any of the following
Stanislas Rolland Sr Feuser Register<=2.5.20
Stanislas Rolland Sr Feuser Register=1.4
Stanislas Rolland Sr Feuser Register=1.6
Stanislas Rolland Sr Feuser Register=2.2.1
Stanislas Rolland Sr Feuser Register=2.2.7
Stanislas Rolland Sr Feuser Register=2.2.8
Stanislas Rolland Sr Feuser Register=2.3
Stanislas Rolland Sr Feuser Register=2.3.6
Stanislas Rolland Sr Feuser Register=2.4
Stanislas Rolland Sr Feuser Register=2.5
Stanislas Rolland Sr Feuser Register=2.5.10
Remediation
Patch Available
Patch Available
Event History
Apr 7, 2009
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
11:30 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·11:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 2, 2022
Advisory Published
via GitHub·03:23 AM
Frequently Asked Questions
1
What is the severity of CVE-2009-1264?
CVE-2009-1264 has a medium severity rating due to its potential to expose sensitive user information.
2
How do I fix CVE-2009-1264?
To fix CVE-2009-1264, upgrade the TYPO3 Frontend User Registration extension to version 2.5.21 or later.
3
Who is affected by CVE-2009-1264?
CVE-2009-1264 affects all versions of the TYPO3 Frontend User Registration extension from 2.5.20 and earlier.
4
What kind of information can be exploited in CVE-2009-1264?
CVE-2009-1264 allows attackers to obtain sensitive information such as passwords from the affected TYPO3 installation.
5
Is CVE-2009-1264 remotely exploitable?
Yes, CVE-2009-1264 can be exploited by remote authenticated users.