Impact
Backend users can move records between pages without edit permissions on the source page, allowing unauthorized manipulation of content. This broken access control flaw, classified as CWE‑862, can compromise the integrity of site data for anyone logged into the administration interface.
Affected Systems
TYPO3 CMS versions 13.0.0‑13.4.30 and 14.0.0‑14.3.2 are affected.
Risk and Exploitability
The CVSS score is 5.3, indicating a moderate impact. The EPSS score is < 1%, showing a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The exploit is most likely performed through the web‑based backend interface by users who have valid credentials, and no additional privileges or conditions are required.
OpenCVE Enrichment
Github GHSA