9.8
CVSSv3

CVE-2022-47406

Published: 14/12/2022 Updated: 19/12/2022
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists in the fe_change_pwd (aka Change password for frontend users) extension prior to 2.0.5, and 3.x prior to 3.0.3, for TYPO3. The extension fails to revoke existing sessions for the current user when the password has been changed.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

change password for frontend users project change password for frontend users