4.2
CVSSv3

CVE-2025-24856

CVSSv4: NA | CVSSv3: 4.2 | CVSSv2: NA | VMScore: 520 | EPSS: 0.00021 | KEV: Not Included
Published: 16/03/2025 Updated: 16/03/2025

Vulnerability Summary

Account Takeover in TYPO3 OIDC Extension Before 4.0.0 via Email Hijacking

An account takeover vulnerability exists in the oidc extension for TYPO3 before version 4.0.0. This security issue involves the account linking logic. An attacker can potentially take over a user's account if specific conditions are met. These conditions include: predicting the user's email address, creating a frontend user account with that email address before the user's first OpenID Connect login, and having an Identity Provider (IDP) that returns the user's email address. The vulnerability allows a pre-hijacking attack that can compromise user account access.

Vulnerable Product Search on Vulmon Subscribe to Product

typo3 oidc