CVE-2025-59019

MEDIUM

TYPO3 CMS 11.0.0-11.5.47 12.0.0-12.4.36 13.0.0-13.4.17 - Unauthorized Information Disclosure via CSV Download Feature

Title source: llm
STIX 2.1

Description

Missing authorization checks in the CSV download feature of TYPO3 CMS versions 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to disclose information from arbitrary database tables stored within the users' web mounts without having access to them.

References (1)

Core 1
Core References

Scores

CVSS v3 4.3
EPSS 0.0005
EPSS Percentile 14.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (3)
typo3/cms-backend 12.0.0 - 12.4.37Packagist
typo3/cms-recordlist 11.0.0 - 12.4.37Packagist
typo3/typo3 11.0.0 - 11.5.48
Published Sep 09, 2025
Tracked Since Feb 18, 2026