Impact
A series of AJAX endpoints used by the backend localization wizard failed to enforce proper authorization checks. As a result, users who could authenticate to the TYPO3 backend but had only low‑privileged roles could retrieve records and content elements that they normally had no permission to view. The flaw does not allow code execution or privilege escalation; it only reduces confidentiality by exposing data to unauthorized backend users.
Affected Systems
TYPO3 CMS versions 10.0.0 through 10.4.59, 11.0.0 through 11.5.53, 12.0.0 through 12.4.48, 13.0.0 through 13.4.34, and 14.0.0 through 14.3.6 are affected.
Risk and Exploitability
The CVSS metric of 5.3 indicates moderate severity, and the EPSS score is not available, so the likelihood of exploitation is unknown but could be low. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a legitimate backend account with low privileges, making the attack internally focused on exposed confidential data rather than external compromise.
OpenCVE Enrichment