Account Takeover in TYPO3 OIDC Extension Before 4.0.0 via Email Hijacking
An account takeover vulnerability exists in the oidc extension for TYPO3 before version 4.0.0. This security issue involves the account linking logic. An attacker can potentially take over a user's account if specific conditions are met. These conditions include: predicting the user's email address, creating a frontend user account with that email address before the user's first OpenID Connect login, and having an Identity Provider (IDP) that returns the user's email address. The vulnerability allows a pre-hijacking attack that can compromise user account access.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
typo3 oidc |