VYPR
Low severity3.7NVD Advisory· Published May 13, 2020· Updated Jun 17, 2026

CVE-2020-11063

CVE-2020-11063

Description

In TYPO3 CMS versions 10.4.0 and 10.4.1, it has been discovered that time-based attacks can be used with the password reset functionality for backend users. This allows an attacker to mount user enumeration based on email addresses assigned to backend user accounts. This has been fixed in 10.4.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
typo3/cms-corePackagist
>= 10.0.0, < 10.4.210.4.2
typo3/cmsPackagist
>= 10.0.0, < 10.4.210.4.2

Affected products

6
  • ghsa-coords3 versions
    >= 10.0.0, < 10.4.2+ 2 more
    • (no CPE)range: >= 10.0.0, < 10.4.2
    • (no CPE)range: >= 10.0.0, < 10.4.2
    • (no CPE)range: >= 10.4.0, <= 10.4.0
  • TYPO3/Typo33 versions
    cpe:2.3:a:typo3:typo3:10.4.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:typo3:typo3:10.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:10.4.1:*:*:*:*:*:*:*
    • (no CPE)range: >= 10.4.0, <= 10.4.1

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.