Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke the corresponding AJAX backend route to disclose sensitive information without having access.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Sep 2025 09:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke the corresponding AJAX backend route to disclose sensitive information without having access. | |
Title | Information Disclosure in Workspaces Module | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: TYPO3
Published:
Updated: 2025-09-09T09:01:10.275Z
Reserved: 2025-09-07T19:01:20.436Z
Link: CVE-2025-59018

No data.

Status : Received
Published: 2025-09-09T09:15:40.907
Modified: 2025-09-09T09:15:40.907
Link: CVE-2025-59018

No data.

No data.