CVE-2022-23501
PHP vulnerability analysis and mitigation

Overview

TYPO3, an open source PHP-based web content management system, was found to contain an Improper Authentication vulnerability (CVE-2022-23501) affecting versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1. The vulnerability was disclosed on December 14, 2022, and allows bypassing frontend login restrictions for specific users organized in different storage folders (partitions) (NVD, TYPO3 Advisory).

Technical details

The vulnerability is classified with a CVSS v3.1 Base Score of 6.5 (MEDIUM) according to NVD, with a vector string of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N. However, TYPO3's own assessment rates it at 5.9 (MEDIUM) with vector string CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N. The vulnerability stems from improper authentication mechanisms in the frontend login system, specifically in how user access restrictions are enforced across different storage partitions (NVD).

Impact

The vulnerability allows potential attackers to bypass user access restrictions and gain access to different accounts within the system. However, it's important to note that the attacker must know the credentials of the target account to successfully exploit this vulnerability (TYPO3 Advisory).

Mitigation and workarounds

The vulnerability has been patched in TYPO3 versions 8.7.49 ELTS, 9.5.38 ELTS, 10.4.33, 11.5.20, and 12.1.1. Users are advised to update to these patched versions to address the security issue (TYPO3 Advisory).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-23622HIGH8.7
  • PHPPHP
  • alextselegidis/easyappointments
NoNoJan 15, 2026
CVE-2025-14894HIGH7.5
  • PHPPHP
  • livewire-filemanager/filemanager
NoNoJan 16, 2026
CVE-2026-23626MEDIUM6.8
  • PHPPHP
  • kimai/kimai
NoYesJan 18, 2026
CVE-2025-69198MEDIUM6
  • PHPPHP
  • pterodactyl/panel
NoYesJan 19, 2026
CVE-2026-23496MEDIUM5.4
  • PHPPHP
  • pimcore/web2print-tools-bundle
NoYesJan 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management