Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend routes without having access to the corresponding backend modules.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-core-sa-2025-021 |
|
History
Wed, 10 Sep 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 09 Sep 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Sep 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Typo3
Typo3 typo3 |
|
| Vendors & Products |
Typo3
Typo3 typo3 |
Tue, 09 Sep 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend routes without having access to the corresponding backend modules. | |
| Title | Broken Access Control in Backend AJAX Routes | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TYPO3
Published: 2025-09-09T09:01:03.951Z
Updated: 2025-09-09T19:30:15.708Z
Reserved: 2025-09-07T19:01:20.436Z
Link: CVE-2025-59017
Updated: 2025-09-09T19:30:12.423Z
Status : Analyzed
Published: 2025-09-09T09:15:40.673
Modified: 2025-09-10T13:44:43.430
Link: CVE-2025-59017
No data.