The backend login has a basic brute force protection implementation which pauses for 5 seconds if wrong credentials are given. This pause however could be bypassed by forging a special request, making brute force attacks on backend editor credentials more feasible.
| Software | From | Fixed in |
|---|---|---|
typo3 / cms
|
6.2.0 | 6.2.14 |
typo3 / cms
|
7.0.0 | 7.3.1 |