The POC for https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-31777 is completely wrong. The CVE CVE-2021-31777 references an issue in TYPO3 Extension "DCE" (see https://typo3.org/security/advisory/typo3-ext-sa-2021-005), not in TYPO3 core.
Your Screencast actually shows the following:
- You login to TYPO3 with a valid backend user
- You edit the attributes of the currently logged in backend user
- You enter a
.
in the fields Start
and Stop
- The dot gets automatically transformed to the current date by TYPO3 (see screenshot of you screencast), since the fields
Start
and Stop
are evaluated as date fields by JavaScript.

- You update the user account
So basically you just disabled the user account by setting the current date in the Stop
field, since the account now is only valid until the configured date and login therefore is not possible any more.