Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend routes without having access to the corresponding backend modules.
History

Wed, 10 Sep 2025 13:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Tue, 09 Sep 2025 23:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Sep 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Typo3
Typo3 typo3
Vendors & Products Typo3
Typo3 typo3

Tue, 09 Sep 2025 09:15:00 +0000

Type Values Removed Values Added
Description Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend routes without having access to the corresponding backend modules.
Title Broken Access Control in Backend AJAX Routes
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TYPO3

Published: 2025-09-09T09:01:03.951Z

Updated: 2025-09-09T19:30:15.708Z

Reserved: 2025-09-07T19:01:20.436Z

Link: CVE-2025-59017

cve-icon Vulnrichment

Updated: 2025-09-09T19:30:12.423Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-09T09:15:40.673

Modified: 2025-09-10T13:44:43.430

Link: CVE-2025-59017

cve-icon Redhat

No data.