Impact
Authenticated backend users can retrieve file metadata via several Backend API routes without appropriate permission checks, granting access to files outside their permitted file mounts or storages. This allows attackers to view confidential file information that should remain hidden, which may assist in reconnaissance or privilege escalation. The vulnerability is an access‑control failure (CWE‑862) and affects TYPO3 CMS versions before 10.4.57, 11.5.50, 12.4.45, 13.4.30 and 14.3.2.
Affected Systems
The vulnerability affects TYPO3 CMS for all major release lines older than the following versions: 10.4.57, 11.5.50, 12.4.45, 13.4.30, and 14.3.2. Backends running any of the listed minor releases before these versions are exposed.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity for this issue. Because the EPSS score is less than 1%, the likelihood of exploitation is considered low, and the vulnerability is not listed in CISA’s KEV catalog. An attacker must have legitimate backend credentials to trigger the flaw, which suggests an internal or compromised account is required. If an attacker can obtain such credentials, the flaw enables information disclosure that can contribute to broader attacks on the system.
OpenCVE Enrichment
Github GHSA