Missing authorization checks in the CSV download feature of TYPO3 CMS versions 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to disclose information from arbitrary database tables stored within the users' web mounts without having access to them.
History

Thu, 11 Sep 2025 21:30:00 +0000

Type Values Removed Values Added
References

Thu, 11 Sep 2025 21:00:00 +0000

Type Values Removed Values Added
References

Wed, 10 Sep 2025 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Tue, 09 Sep 2025 23:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Sep 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Typo3
Typo3 typo3
Vendors & Products Typo3
Typo3 typo3

Tue, 09 Sep 2025 09:15:00 +0000

Type Values Removed Values Added
Description Missing authorization checks in the CSV download feature of TYPO3 CMS versions 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to disclose information from arbitrary database tables stored within the users' web mounts without having access to them.
Title Information Disclosure via CSV Download
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TYPO3

Published: 2025-09-09T09:01:17.787Z

Updated: 2025-09-11T20:44:40.074Z

Reserved: 2025-09-07T19:01:20.436Z

Link: CVE-2025-59019

cve-icon Vulnrichment

Updated: 2025-09-09T19:29:30.307Z

cve-icon NVD

Status : Modified

Published: 2025-09-09T09:15:41.113

Modified: 2025-09-11T21:15:34.930

Link: CVE-2025-59019

cve-icon Redhat

No data.