typo3 - Login Handling is susceptible to open redirection which allows attackers redirecting to arbitrary content, and conducting phishing attacks. No authentication is required. (CVE-2021-21338)
https://typo3.org/security/advisory/typo3-core-sa-2021-001
Comme le soleil, les machines ne se couchent jamais.