CVE-2024-55894

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 14, 2025
CWE ID 749
CWE ID 352

Summary

CVE-2024-55894 is a vulnerability affecting the TYPO3 Content Management Framework. The issue lies in the backend user interface, which is susceptible to Cross-Site Request Forgery (CSRF) attacks. Malicious URLs can trick users into initiating state-changing actions, such as password resets or session terminations, for other backend users. This vulnerability can be exploited when the user opens a malicious link while certain settings, including `security.backend.enforceReferrer` and `BE/cookieSameSite`, are misconfigured. TYPO3 users are advised to update to versions 11.5.42 ELTS, 12.4.25 LTS, and 13.4.3 LTS to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share