Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend routes without having access to the corresponding backend modules.
History

Tue, 09 Sep 2025 09:15:00 +0000

Type Values Removed Values Added
Description Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend routes without having access to the corresponding backend modules.
Title Broken Access Control in Backend AJAX Routes
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TYPO3

Published:

Updated: 2025-09-09T09:01:03.951Z

Reserved: 2025-09-07T19:01:20.436Z

Link: CVE-2025-59017

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-09-09T09:15:40.673

Modified: 2025-09-09T09:15:40.673

Link: CVE-2025-59017

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.