Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend routes without having access to the corresponding backend modules.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://typo3.org/security/advisory/typo3-core-sa-2025-021 |
![]() ![]() |
History
Wed, 10 Sep 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* | |
Metrics |
cvssV3_1
|
Tue, 09 Sep 2025 23:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 09 Sep 2025 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Typo3
Typo3 typo3 |
|
Vendors & Products |
Typo3
Typo3 typo3 |
Tue, 09 Sep 2025 09:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend routes without having access to the corresponding backend modules. | |
Title | Broken Access Control in Backend AJAX Routes | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: TYPO3
Published: 2025-09-09T09:01:03.951Z
Updated: 2025-09-09T19:30:15.708Z
Reserved: 2025-09-07T19:01:20.436Z
Link: CVE-2025-59017

Updated: 2025-09-09T19:30:12.423Z

Status : Analyzed
Published: 2025-09-09T09:15:40.673
Modified: 2025-09-10T13:44:43.430
Link: CVE-2025-59017

No data.