Impact
TYPO3 CMS allows a backend administrator with normal administrative rights, not system maintainer privileges, to schedule internal configuration commands. This missing authorization lets the user modify, read, or set configuration values, potentially elevating privileges to system maintainer or causing system failure. The vulnerability stems from a privilege escalation flaw (CWE-266 and CWE-862).
Affected Systems
The flaw affects TYPO3 CMS versions 14.2.0 through 14.3.6, where normal administrators can execute low‑level commands that normally require system maintainer rights. Versions before 14.2.0 and after 14.3.6 are not impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, yet EPSS is not available and the vulnerability is not listed in CISA KEV. Exploitation requires an authenticated backend administrator account, and the attacker uses the web‑based administration interface to trigger configuration commands. Because the flaw allows privilege escalation and configuration tampering, a successful exploit can lead to unauthorized system changes or denial of service.
OpenCVE Enrichment