HomeSecurityNew update for TYPO 3 CMS fixes important issues

New update for TYPO 3 CMS fixes significant problems

typo 3

TYPO 3, which is advertised as the most widespread and widely used corporate Content Management system, was recently updated with an update, aiming to fix vulnerabilities that existed in the system, such as cross-site scripting (XSS), as well as blocking unauthorized access.

The CMS TYPO 3 was developed for use by businesses and public organizations and, according to the company's official statistics, has over 500,000 installations.

The changelog in the recent update resolves two XSS issues, one related to Flowplayer and the other to the Filelist component. The first issue was reported by Wouter van Dongen and the other by Markus Bucher, developers who actively contributed to the development of the Typo 3 platform.

Another bug that was identified and fixed with the current update, reported by Helmut Hummel, concerns authentication. Older versions of the CMS (6.2.0 to 6.2.13 and 7.0.0 to 7.3.0) are particularly vulnerable to the authentication system for logging into the system.

The bug report even states that "If the user's identity is verified in anonymous mode, their id does not change, which may allow attackers to create a valid id, via cross-site scripting (XSS), and gain access to the system.".

Brute force attack protection mechanisms for frontend login have been introduced in the current version of TYPO 3 CMS, which now enforces a five-second delay between incorrect login entries. In addition, the possibility of implementing other brute force attack protection methods is also offered.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS