CVE-2025-59017

HIGH

TYPO3 CMS 9.0.0-13.4.17 - Missing Authorization in Backend Routing

Title source: llm
STIX 2.1

Description

Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend routes without having access to the corresponding backend modules.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0008
EPSS Percentile 23.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (6)
typo3/cms-backend 9.0.0 - 12.4.37Packagist
typo3/cms-beuser 13.0.0 - 13.4.18Packagist
typo3/cms-dashboard 10.0.0 - 12.4.37Packagist
typo3/cms-recycler 9.0.0 - 12.4.37Packagist
typo3/cms-workspaces 9.0.0 - 12.4.37Packagist
typo3/typo3 9.0.0 - 9.5.55
Published Sep 09, 2025
Tracked Since Feb 18, 2026