Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27227 | Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke the corresponding AJAX backend route to disclose sensitive information without having access. |
Github GHSA |
GHSA-w2pf-7q5w-2cgw | TYPO3 Workspaces Module Information Disclosure |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-core-sa-2025-022 |
|
Thu, 11 Sep 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 11 Sep 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 10 Sep 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 09 Sep 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Sep 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Typo3
Typo3 typo3 |
|
| Vendors & Products |
Typo3
Typo3 typo3 |
Tue, 09 Sep 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke the corresponding AJAX backend route to disclose sensitive information without having access. | |
| Title | Information Disclosure in Workspaces Module | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TYPO3
Published:
Updated: 2025-09-11T20:35:36.245Z
Reserved: 2025-09-07T19:01:20.436Z
Link: CVE-2025-59018
Updated: 2025-09-09T19:29:50.296Z
Status : Analyzed
Published: 2025-09-09T09:15:40.907
Modified: 2025-09-26T14:08:37.780
Link: CVE-2025-59018
No data.
OpenCVE Enrichment
Updated: 2025-09-09T21:31:33Z
EUVD
Github GHSA