Medium severity5.4NVD Advisory· Published Dec 14, 2022· Updated Jun 17, 2026
CVE-2022-47406
CVE-2022-47406
Description
An issue was discovered in the fe_change_pwd (aka Change password for frontend users) extension before 2.0.5, and 3.x before 3.0.3, for TYPO3. The extension fails to revoke existing sessions for the current user when the password has been changed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
typo3/cmsPackagist | < 2.0.5 | 2.0.5 |
typo3/cmsPackagist | >= 3.0.0, < 3.0.3 | 3.0.3 |
derhansen/fe_change_pwdPackagist | >= 3.0.0, < 3.0.3 | 3.0.3 |
derhansen/fe_change_pwdPackagist | < 2.0.5 | 2.0.5 |
Affected products
4- TYPO3/Change password for frontend usersdescription
- cpe:2.3:a:change_password_for_frontend_users_project:change_password_for_frontend_users:*:*:*:*:*:typo3:*:*Range: <2.0.5
- ghsa-coords2 versions
< 2.0.5+ 1 more
- (no CPE)range: < 2.0.5
- (no CPE)range: >= 3.0.0, < 3.0.3
Patches
Vulnerability mechanics
References
4- typo3.org/security/advisory/typo3-ext-sa-2022-016nvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-53mm-hx32-6475ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-47406ghsaADVISORY
- github.com/FriendsOfPHP/security-advisories/blob/master/derhansen/fe_change_pwd/CVE-2022-47406.yamlghsaWEB
News mentions
0No linked articles in our index yet.