Skip to content

CVE-2014-3944

The Authentication component in TYPO3 6.2.0 before 6.2.3 does not properly invalidate timed out user sessions, which allows remote attackers to bypass authentication via unspecified vectors.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0019 (0.2%)
Percentile: 40.1%
EPSS: 2026-05-06

Affects

typo3:typo3

Technical description

The Authentication component in TYPO3 6.2.0 before 6.2.3 does not properly invalidate timed out user sessions, which allows remote attackers to bypass authentication via unspecified vectors.

Published: 6/3/2014, 2:55:11 PM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam