Unverified Ownership
CVE-2025-47940
Summary
TYPO3 is an open source, PHP based web content management system. In affected versions, administrator-level backend users without system maintainer privileges can escalate their privileges and gain system maintainer access. Exploiting this vulnerability requires a valid administrator account. This issue affects typo3/cms-core, typo3/cms, typo3/cms-setup, and typo3/cms-backend versions 10.4.x prior to 10.4.50, 11.0.x prior to 11.5.44, 12.0.x prior to 12.4.31, and 13.0.x prior to 13.4.12.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- HIGH
- HIGH
- HIGH
CWE-283 - Unverified Ownership
The software does not properly verify that a critical resource is owned by the proper entity.
Advisory Timeline
- Published