Skip to main navigation Skip to main content Skip to page footer

Information Disclosure in third party extension "Frontend User registration"

It has been discovered that the TYPO3 extension "Frontend User Registration" (sr_feuser_register) is susceptible to Information Disclosure.

Release Date: April 6, 2009

Component Type: Third party extension. This extension is not a part of a TYPO3 default installation.

Affected Versions: 2.5.20 and all versions below

Vulnerability Type: Information Disclosure

Severity: High

Problem Description: Failing to properly check access rights, the extension is susceptible to information disclosure, making it possible for a logged in frontend user to get hold of information (including the password) of other frontend user records.

Solution: An updated version 2.5.21 is available from the TYPO3 extension manager and at http://typo3.org/extensions/repository/view/sr_feuser_register/2.5.21/. Users of the extension are advised to update the extension as soon as possible.

Credits: Credits go to Thomas Renner and Christian Münch, who discovered the issue and Steffen Gebert who reported it to us.

 

General advice: Follow the recommendations that are given in the TYPO3 SECURITY Guide. Please subscribe to the typo3-announce mailing list in order to receive future Security Bulletins via E-mail.