Impact
Backend users were able to move records to a different page without having edit permissions on the source page. This broken access control flaw, classified as CWE‑862, allows backend users lacking edit rights on a source page to relocate records to a new page, effectively bypassing the intended permissions model.
Affected Systems
TYPO3 CMS versions 13.0.0‑13.4.30 and 14.0.0‑14.3.2 are affected.
Risk and Exploitability
The CVSS score is 5.3, indicating a moderate impact level. The EPSS score of < 1% shows a very low probability of exploitation and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is through the web‑based backend interface, requiring only valid user credentials; no additional privileges or conditions are required.
OpenCVE Enrichment
Github GHSA