CVE-2021-21338
Open Redirection in Login Handling
6.1
MEDIUM
CVSS 3.1
EPSS 1.1%
Description
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been discovered that Login Handling is susceptible to open redirection which allows attackers redirecting to arbitrary content, and conducting phishing attacks. No authentication is required in order to exploit this vulnerability. This is fixed in versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1.
How to fix CVE-2021-21338
To remediate CVE-2021-21338, upgrade the affected package to a fixed version below.
- —upgrade to 10.4.14 or later
- —upgrade to 6.2.57 or later
Is CVE-2021-21338 being exploited?
Low — EPSS is 1.1%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- >= 10.0.0, < 10.4.14
- >= 6.2.0, < 6.2.57
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |