Impact
Authenticated backend users can call certain Backend API routes to retrieve file metadata without proper permission checks, allowing them to access files outside their designated mounts or storages. Because the API does not enforce the normal file‑mount restrictions for backend users, an attacker with a valid backend account can view metadata for files that should be inaccessible. This exposure enables information disclosure that may aid further reconnaissance or privilege escalation. The vulnerability is an access‑control failure (CWE‑862).
Affected Systems
The vulnerability affects TYPO3 CMS for all major release lines older than the following versions: 10.4.57, 11.5.50, 12.4.45, 13.4.30, and 14.3.2. Backends running any of the listed minor releases before these versions are exposed.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity for this issue. Because the EPSS score is less than 1%, the likelihood of exploitation is considered low, and the vulnerability is not listed in CISA’s KEV catalog. An attacker must have legitimate backend credentials to trigger the flaw, which suggests an internal or compromised account is required. If an attacker can obtain such credentials, the flaw enables information disclosure that can contribute to broader attacks on the system.
OpenCVE Enrichment
Github GHSA