CVE-2025-24856 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

An issue was discovered in the oidc (aka OpenID Connect Authentication) extension before 4.0.0 for TYPO3. The account linking logic allows a pre-hijacking attac…
Medium CVSS: 4.2

CVE-2025-24856

An issue was discovered in the oidc (aka OpenID Connect Authentication) extension before 4.0.0 for TYPO3. The account linking logic allows a pre-hijacking attack, leading to Account Takeover. The attack can only be exploited if the following requirements are met: (1) an attacker can anticipate the e-mail address of the user, (2) an attacker can register a public frontend user account using that e-mail address before the user's first OIDC login, and (3) the IDP returns an email field containing the e-mail address of the user,
Vendor
-
Product
-
CWE
CWE-348
Yayın Tarihi
2025-03-16 04:15:14
Güncelleme
2025-03-16 04:15:14
Source Identifier
cve@mitre.org
KEV Date Added
-

Kategoriler

Referanslar