Impact
A flaw in TYPO3 CMS enables backend users who can reach the Recycler module to restore soft‑deleted records on pages or tables that they are not authorized to modify. By bypassing built‑in deletion safeguards, an attacker can alter content and potentially leak or corrupt data, violating both data integrity and privacy rules.
Affected Systems
TYPO3 CMS versions earlier than 10.4.57, 11.0.0 through 11.5.50, 12.0.0 through 12.4.45, 13.0.0 through 13.4.30, and 14.0.0 through 14.3.2 are impacted. The vulnerability resides in the Recycler module of these releases.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is 0.00238 (less than 1%) and the vulnerability is not listed in CISA KEV, suggesting low but non-zero exploitation probability. An attacker must first possess authenticated backend access and the privilege to use the Recycler module; only then can they craft a request to restore a soft‑deleted record, effectively elevating their capability to modify content they should not control.
OpenCVE Enrichment
Github GHSA