Description
A deterministic three‑character prefix in the Password Generation component of TYPO3 CMS versions 12.0.0–12.4.36 and 13.0.0–13.4.17 reduces entropy, allowing attackers to carry out brute‑force attacks more quickly.
Problem types
Product status
12.0.0 (semver) before 12.4.37
13.0.0 (semver) before 13.4.18
Credits
Mathias Brodala
Oliver Hader
References
typo3.org/security/advisory/typo3-core-sa-2025-019