Impact
Backend users with access to the Recycler module can restore soft‑deleted records on pages or for tables they are not authorized to modify. This bypasses built‑in deletion safeguards and allows unauthorized content changes, compromising data integrity and privacy.
Affected Systems
TYPO3 CMS versions earlier than 10.4.57, 11.0.0 through 11.5.50, 12.0.0 through 12.4.45, 13.0.0 through 13.4.30, and 14.0.0 through 14.3.2 are impacted. The vulnerability resides in the Recycler module of these releases.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is < 1% and the vulnerability is not listed in CISA KEV, suggesting low but non‑zero exploitation probability. Based on the description, it is inferred that an attacker must first possess authenticated backend access and the privilege to use the Recycler module; only then can they craft a request to restore a soft‑deleted record, effectively elevating their capability to modify content they should not control.
OpenCVE Enrichment
Github GHSA