Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke the corresponding AJAX backend route to disclose sensitive information without having access.
History

Thu, 11 Sep 2025 21:30:00 +0000


Thu, 11 Sep 2025 20:45:00 +0000

Type Values Removed Values Added
References

Wed, 10 Sep 2025 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Tue, 09 Sep 2025 23:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Sep 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Typo3
Typo3 typo3
Vendors & Products Typo3
Typo3 typo3

Tue, 09 Sep 2025 09:15:00 +0000

Type Values Removed Values Added
Description Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke the corresponding AJAX backend route to disclose sensitive information without having access.
Title Information Disclosure in Workspaces Module
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TYPO3

Published: 2025-09-09T09:01:10.275Z

Updated: 2025-09-11T20:35:36.245Z

Reserved: 2025-09-07T19:01:20.436Z

Link: CVE-2025-59018

cve-icon Vulnrichment

Updated: 2025-09-09T19:29:50.296Z

cve-icon NVD

Status : Modified

Published: 2025-09-09T09:15:40.907

Modified: 2025-09-11T21:15:34.773

Link: CVE-2025-59018

cve-icon Redhat

No data.