VYPR
Moderate severityNVD Advisory· Published Jun 3, 2014· Updated May 6, 2026

CVE-2014-3941

CVE-2014-3941

Description

TYPO3 CMS fails to validate the HTTP Host header, enabling host spoofing attacks that can lead to URL manipulation and phishing.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

TYPO3 CMS fails to validate the HTTP Host header, enabling host spoofing attacks that can lead to URL manipulation and phishing.

Vulnerability

TYPO3 CMS versions 4.5.0 to 4.5.33, 4.7.0 to 4.7.18, 6.0.0 to 6.0.13, 6.1.0 to 6.1.8, and 6.2.0 to 6.2.2 are vulnerable to a host spoofing vulnerability. The application does not properly validate the HTTP Host header, which is used to generate absolute URLs in various components such as 404 handling, HTTPS enforcement, and password reset links. This allows an attacker to supply an arbitrary host value in the request header [1].

Exploitation

An unauthenticated remote attacker can craft an HTTP request with a spoofed Host header targeting any TYPO3 page that relies on the header to construct URLs. No special network position or authentication is required; the attacker can trigger the vulnerability from any network that can reach the server. The TYPO3 CMS generates responses containing absolute URLs that incorporate the attacker-controlled host value [1].

Impact

Successful exploitation enables an attacker to manipulate the host portion of URLs generated by the CMS. This can be leveraged for phishing attacks, cache poisoning, and password reset poisoning, where victims receive links pointing to attacker-controlled domains. The integrity of generated links is compromised, potentially leading to further attacks such as session theft or credential capture. The CVSS v2 score is 5.0 (AV:N/AC:M/Au:N/C:N/I:P/A:N), indicating medium severity with partial integrity impact [1].

Mitigation

Upgrade to TYPO3 CMS versions 4.5.34, 4.7.19, 6.0.14, 6.1.9, or 6.2.3, which were released on May 22, 2014. The fix introduces the configuration option $GLOBALS['TYPO3_CONF_VARS']['SYS']['trustedHostsPattern'], which defaults to SERVER_NAME to validate the submitted Host header against the server's trusted host name. Administrators should also review web server configuration for name-based virtual hosts to ensure only legitimate host names are accepted [1].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
typo3/cmsPackagist
>= 4.5.0, < 4.5.344.5.34
typo3/cmsPackagist
>= 4.7.0, < 4.7.194.7.19
typo3/cmsPackagist
>= 6.0.0, < 6.0.146.0.14
typo3/cmsPackagist
>= 6.1.0, < 6.1.96.1.9
typo3/cmsPackagist
>= 6.2.0, < 6.2.36.2.3

Affected products

83
  • TYPO3/Typo382 versions
    cpe:2.3:a:typo3:typo3:4.5.0:*:*:*:*:*:*:*+ 81 more
    • cpe:2.3:a:typo3:typo3:4.5.0:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.10:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.11:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.12:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.13:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.14:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.15:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.16:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.17:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.18:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.19:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.2:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.20:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.21:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.22:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.23:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.24:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.25:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.26:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.27:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.28:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.29:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.3:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.30:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.31:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.32:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.33:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.4:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.5:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.6:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.7:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.8:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.9:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.7.1:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.7.10:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.7.11:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.7.12:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.7.13:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.7.14:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.7.15:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.7.16:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.7.17:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.7.18:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.7.2:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.7.3:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.7.4:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.7.5:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.7.6:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.7.7:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.7.8:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.7.9:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.0.10:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.0.11:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.0.12:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.0.13:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.1.4:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.1.6:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.1.7:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.1.8:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.2:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.2.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.2.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.2.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:6.2.2:*:*:*:*:*:*:*
  • ghsa-coords
    Range: >= 4.5.0, < 4.5.34

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

11

News mentions

0

No linked articles in our index yet.