MEDIUM · 5.0

CVE-2012-5890

The Front End User Registration (sr_feuser_register) extension before 2.6.2 for TYPO3 allows remote attackers to obtain user names and passwords via the (1) edit perspective or (2) autologin feature.

Vulnerability Description

The Front End User Registration (sr_feuser_register) extension before 2.6.2 for TYPO3 allows remote attackers to obtain user names and passwords via the (1) edit perspective or (2) autologin feature.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Stanislas RollandSr Feuser Register<= 2.6.1
Typo3Typo3-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-5890?

CVE-2012-5890 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The Front End User Registration (sr_feuser_register) extension before 2.6.2 for TYPO3 allows remote attackers to obtain user names and passwords via the (1) edit perspective or (2) autologin feature.

How severe is CVE-2012-5890?

CVE-2012-5890 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-5890?

Check the references section above for vendor advisories and patch information. Affected products include: Stanislas Rolland Sr Feuser Register, Typo3 Typo3.