CVE-2022-36105

User Enumeration via Response Timing in TYPO3

TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that observing response time during user authentication (backend and frontend) can be used to distinguish between existing and non-existing user accounts. Extension authors of 3rd party TYPO3 extensions providing a custom authentication service should check if the extension is affected by the described problem. Affected extensions must implement new `MimicServiceInterface::mimicAuthUser`, which simulates corresponding times regular processing would usually take. Update to TYPO3 version 7.6.58 ELTS, 8.7.48 ELTS, 9.5.37 ELTS, 10.4.32 or 11.5.16 that fix this problem. There are no known workarounds for this issue.


We have discovered 26 live websites that are affected by CVE-2022-36105.

Run a Free Instant Scan




Affected Software

Product  TYPO3 CMS
Category Content Management System
Vulnerable Domains26 live websites (0.20% of TYPO3 CMS install base)
Vulnerable Versions
  • from 7 through 7.6.58
  • from 8 through 8.7.48
  • from 9 through 9.5.37
  • from 10 through 10.4.32
  • from 11 through 11.5.16
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-203 Observable Discrepancy



Details

  • Published - Sep 13, 2022
  • Updated - Apr 23, 2025

Website Distribution by Country

Number of websites using CVE-2022-36105
Germany18 websites
Austria4 websites
Switzerland1 websites
Czech Republic1 websites
Netherlands1 websites
Slovenia1 websites

Website Distribution by TLD

Number of websites using CVE-2022-36105
.de12 websites
.at6 websites
.com2 websites
.ch1 websites
.cz1 websites
.net1 websites
.nl1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2022-36105

Top websites that are affected by CVE-2022-36105. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.de Germany***,***
*****.de Germany*,***,***
*************************.de Germany*,***,***
****.ch Switzerland*,***,***
***.**.si Slovenia*,***,***
*********.**************.de Germany*,***,***
*************.net Germany*,***,***
**************************.de Germany*,***,***
******************.de Germany*,***,***
****************.com Germany**,***,***
See full domain list

FAQ

CVE-2022-36105 is Observable Discrepancy in TYPO3 CMS
A total of 26 websites have been identified as vulnerable to CVE-2022-36105, based on global website indexing conducted by WebTechSurvey.
The TYPO3 CMS is affected by the CVE-2022-36105 vulnerability.
TYPO3 CMS versions up to 11.5.16 are vulnerable to CVE-2022-36105.
CVE-2022-36105 is resolved in version 11.5.16 of TYPO3 CMS.