Skip to main content

Unverified Ownership

CVE-2025-47940

Severity High
Score 7.2/10

Summary

TYPO3 is an open source, PHP based web content management system. In affected versions, administrator-level backend users without system maintainer privileges can escalate their privileges and gain system maintainer access. Exploiting this vulnerability requires a valid administrator account. This issue affects typo3/cms-core, typo3/cms, typo3/cms-setup, and typo3/cms-backend versions 10.4.x prior to 10.4.50, 11.0.x prior to 11.5.44, 12.0.x prior to 12.4.31, and 13.0.x prior to 13.4.12.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • HIGH
  • HIGH
  • HIGH

CWE-283 - Unverified Ownership

The software does not properly verify that a critical resource is owned by the proper entity.

Advisory Timeline

  • Published