High severityNVD Advisory· Published Apr 7, 2009· Updated Jun 16, 2026
CVE-2009-1264
CVE-2009-1264
Description
Frontend User Registration (sr_feuser_register) extension 2.5.20 and earlier for TYPO3 does not properly verify access rights, which allows remote authenticated users to obtain sensitive information such as passwords via unknown attack vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
sjbr/sr-feuser-registerPackagist | < 2.5.21 | 2.5.21 |
Affected products
12cpe:2.3:a:stanislas_rolland:sr_feuser_register:*:*:*:*:*:*:*:*+ 10 more
- cpe:2.3:a:stanislas_rolland:sr_feuser_register:*:*:*:*:*:*:*:*range: <=2.5.20
- cpe:2.3:a:stanislas_rolland:sr_feuser_register:1.4:*:*:*:*:*:*:*
- cpe:2.3:a:stanislas_rolland:sr_feuser_register:1.6:*:*:*:*:*:*:*
- cpe:2.3:a:stanislas_rolland:sr_feuser_register:2.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:stanislas_rolland:sr_feuser_register:2.2.7:*:*:*:*:*:*:*
- cpe:2.3:a:stanislas_rolland:sr_feuser_register:2.2.8:*:*:*:*:*:*:*
- cpe:2.3:a:stanislas_rolland:sr_feuser_register:2.3:*:*:*:*:*:*:*
- cpe:2.3:a:stanislas_rolland:sr_feuser_register:2.3.6:*:*:*:*:*:*:*
- cpe:2.3:a:stanislas_rolland:sr_feuser_register:2.4:*:*:*:*:*:*:*
- cpe:2.3:a:stanislas_rolland:sr_feuser_register:2.5:*:*:*:*:*:*:*
- cpe:2.3:a:stanislas_rolland:sr_feuser_register:2.5.10:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
11- typo3.org/extensions/repository/view/sr_feuser_register/2.5.21/nvdPatchVendor Advisory
- typo3.org/teams/security/security-bulletins/typo3-sa-2009-004/nvdPatchVendor Advisory
- www.securityfocus.com/bid/34374nvdPatch
- www.vupen.com/english/advisories/2009/0938nvdPatchVendor Advisory
- secunia.com/advisories/34586nvdVendor Advisory
- github.com/advisories/GHSA-rjrq-93hp-22wwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2009-1264ghsaADVISORY
- typo3.org/extensions/repository/view/sr_feuser_register/2.5.21ghsaWEB
- web.archive.org/web/20090527190538/http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-004ghsaWEB
- web.archive.org/web/20200228205603/http://www.securityfocus.com/bid/34374ghsaWEB
- osvdb.org/53278nvd
News mentions
0No linked articles in our index yet.