Vulnerability DatabaseGHSA-m96r-7vqm-j95g

GHSA-m96r-7vqm-j95g
PHP vulnerability analysis and mitigation

Overview

The vulnerability (GHSA-m96r-7vqm-j95g) titled 'Information Disclosure in User Authentication' was discovered in TYPO3 CMS and disclosed on May 7, 2019. This security issue affected TYPO3 CMS versions 9.0.0 through 9.5.5. The vulnerability was classified as medium severity and involved the exposure of user credentials in system logs (TYPO3 Advisory).

Technical details

The vulnerability occurred when login failures were logged on the default stream with log level 'warning', which inadvertently included plain-text user credentials. The suggested CVSS v3.0 score metrics are AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N, indicating a medium severity level (TYPO3 Advisory).

Impact

This vulnerability could lead to the exposure of user credentials through system logs, potentially compromising user account security. The impact was significant enough to warrant a security advisory, though it required specific conditions to be exploited (GitHub Advisory).

Exploitability

The vulnerability required local access to system logs and specific conditions to be exploited. The CVSS metrics indicate that exploitation needed network access (AV:N), high attack complexity (AC:H), low privileges (PR:L), and user interaction (UI:R) (TYPO3 Advisory).

Mitigation and workarounds

The vulnerability was fixed in TYPO3 version 9.5.6. The fix involved changing the log level for failed login attempts from 'warning' to 'debug', which needs to be enabled explicitly. Users are advised to update to version 9.5.6 or later to address this security issue (TYPO3 Advisory).

Community reactions

The vulnerability was discovered and fixed by Helmut Hummel, who received credit for reporting and addressing the issue (TYPO3 Advisory).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-56825HIGH8.1
  • PHP logoPHP
  • shopper/framework
NoYesSep 11, 2026
CVE-2026-56829HIGH8.1
  • PHP logoPHP
  • shopper/framework
NoYesSep 11, 2026
CVE-2026-56830MEDIUM6.5
  • PHP logoPHP
  • shopper/framework
NoYesSep 11, 2026
CVE-2026-56831MEDIUM6.5
  • PHP logoPHP
  • shopper/framework
NoYesSep 11, 2026
CVE-2026-49992MEDIUM6.3
  • PHP logoPHP
  • kimai/kimai
NoYesSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management