Filtered by vendor Typo3 Subscriptions
Filtered by product Extension "e-mail Mfa Provider" Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2026-4208 1 Typo3 1 Extension "e-mail Mfa Provider" 2026-03-18 N/A
The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible MFA bypass for future login attempts by providing an empty string as MFA code to the extensions MFA provider.