CVE-2010-1022:
TYPO3 Authentication Bypass via Salted user password hashes extension
7.5
CVSS ScoreBasic Information
CVE ID
GHSA ID
EPSS Score
-
CWE
Published
5/2/2022
Updated
2/14/2024
KEV Status
No
Technology
PHP
Technical Details
CVSS Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
---|---|---|---|
typo3/cms-saltedpasswords | composer | < 0.2.13 | 0.2.13 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The advisory was withdrawn due to incorrect package identification (typo3/cms-saltedpasswords vs. t3sec_saltedpw). No code diffs, patch details, or specific technical descriptions of the exploit vectors are provided in the available sources. The vulnerability description mentions 'unspecified vectors,' and the lack of concrete implementation details makes it impossible to confidently identify specific vulnerable functions. The withdrawal of the advisory further reduces confidence in the accuracy of the original package attribution.