Looking for the vulnerability index of Invicti's legacy products?
TYPO3 Unverified Password Change Vulnerability - CVE-2025-47938 - Vulnerability Database

TYPO3 Unverified Password Change Vulnerability - CVE-2025-47938

Low
Reference: CVE-2025-47938
Title: TYPO3 Unverified Password Change Vulnerability
Overview:

TYPO3 is an open source PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS 10.4.50 ELTS 11.5.44 ELTS 12.4.31 LTS and 13.4.12 LTS the backend user management interface allows password changes without requiring the current password. When an administrator updates their own account or modifies other user accounts via the admin interface the current password is not requested for verification. This behavior may lower the protection against unauthorized access in scenarios where an admin session is hijacked or left unattended as it enables password changes without additional authentication. Users should update to TYPO3 version 9.5.51 ELTS 10.4.50 ELTS 11.5.44 ELTS 12.4.31 LTS or 13.4.12 LTS to fix the problem.