CVE-2022-31050 MEDIUM

CVE-2022-31050: Insufficient Session Expiration in TYPO3 Admin Tool

Vendor Typo3
Product typo3
Weakness CWE-613 · Insufficient session expiration
Published June 14, 2022
Last update April 23, 2025

CVSS base score

6.0/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L

What the vulnerability does

Description

TYPO3 is an open source web content management system. Prior to versions 9.5.34 ELTS, 10.4.29, and 11.5.11, Admin Tool sessions initiated via the TYPO3 backend user interface had not been revoked even if the corresponding user account was degraded to lower permissions or disabled completely. This way, sessions in the admin tool theoretically could have been prolonged without any limit. TYPO3 versions 9.5.34 ELTS, 10.4.29, and 11.5.11 contain a fix for the problem.

Key dates

Disclosure timeline

June 14, 2022 CVE published
April 23, 2025 Record updated