Description
TYPO3 before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness during generation of a hash with the "forgot password" function.
Remediation
References
Related Vulnerabilities
phpBB Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-5501)
Caddy Web Server Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2026-27589)
MySQL CVE-2017-10365 Vulnerability (CVE-2017-10365)
WordPress Plugin Telefication Server-Side Request Forgery (1.8.0)
Oracle Application Server Other Vulnerability (CVE-2007-0289)