CVE-2025-12998

HIGH

TYPO3 Extension Modules <4.3.11-5.7.4-6.4.2-7.5.5 - Auth Bypass

Title source: llm
STIX 2.1

Description

Improper Authentication vulnerability in TYPO3 Extension "Modules" codingms/modules.This issue affects Extension "Modules": before 4.3.11, from 5.0.0 before 5.7.4, from 6.0.0 before 6.4.2, from 7.0.0 before 7.5.5.

References (1)

Core 1

Scores

CVSS v4 8.2
EPSS 0.0039
EPSS Percentile 30.6%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (5)
codingms/modules 0 - 4.3.11Packagist
TYPO3/Extension "Modules" < 4.3.11
TYPO3/Extension "Modules" 5.0.0 - 5.7.4
TYPO3/Extension "Modules" 6.0.0 - 6.4.2
TYPO3/Extension "Modules" 7.0.0 - 7.5.5
Published Nov 12, 2025
Tracked Since Feb 18, 2026