CVE-2025-59017
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-09-09
Last updated on: 2025-09-10
Assigner: TYPO3
Description
Description
Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend routes without having access to the corresponding backend modules.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| typo3 | typo3 | From 9.0.0 (inc) to 9.5.55 (exc) |
| typo3 | typo3 | From 10.0.0 (inc) to 10.4.54 (exc) |
| typo3 | typo3 | From 11.0.0 (inc) to 11.5.48 (exc) |
| typo3 | typo3 | From 12.0.0 (inc) to 12.4.37 (exc) |
| typo3 | typo3 | From 13.0.0 (inc) to 13.4.18 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |