CVE-2010-0286
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/02/2010
Last modified:
11/04/2025
Description
Unspecified vulnerability in the OpenID Identity Authentication extension in TYPO3 4.3.0 allows remote attackers to bypass authentication and gain access to a backend user account via unknown attack vectors in which both the attacker and victim have an OpenID provider that discards identities during authentication.
Impact
Base Score 2.0
5.10
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:typo3:typo3:4.3.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://osvdb.org/61680
- http://secunia.com/advisories/38206
- http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-001/
- http://www.vupen.com/english/advisories/2010/0127
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55609
- http://osvdb.org/61680
- http://secunia.com/advisories/38206
- http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-001/
- http://www.vupen.com/english/advisories/2010/0127
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55609



