#VU67216 Operation on a Resource after Expiration or Release in TYPO3 - CVE-2022-36106
Published: September 13, 2022
TYPO3
TYPO3
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to missing check for expiration time of a password reset link for backend users. A remote attacker can brute force the password reset token and perform a password reset even if the default expiry time of two hours has been exceeded.