CVE-2025-59015

MEDIUM

TYPO3 CMS <13.4.17 - Info Disclosure

Title source: llm

Description

A deterministic three‑character prefix in the Password Generation component of TYPO3 CMS versions 12.0.0–12.4.36 and 13.0.0–13.4.17 reduces entropy, allowing attackers to carry out brute‑force attacks more quickly.

Scores

CVSS v3 6.5
EPSS 0.0003
EPSS Percentile 9.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Classification

CWE
CWE-331
Status published

Affected Products (2)

typo3/typo3 < 12.4.37
typo3/cms-core < 12.4.37Packagist

Timeline

Published Sep 09, 2025
Tracked Since Feb 18, 2026