Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend routes without having access to the corresponding backend modules.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://typo3.org/security/advisory/typo3-core-sa-2025-021 |
![]() ![]() |
History
Tue, 09 Sep 2025 09:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend routes without having access to the corresponding backend modules. | |
Title | Broken Access Control in Backend AJAX Routes | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: TYPO3
Published:
Updated: 2025-09-09T09:01:03.951Z
Reserved: 2025-09-07T19:01:20.436Z
Link: CVE-2025-59017

No data.

Status : Received
Published: 2025-09-09T09:15:40.673
Modified: 2025-09-09T09:15:40.673
Link: CVE-2025-59017

No data.

No data.