Skip to main content

Exposure of Sensitive Information to an Unauthorized Actor

CVE-2025-59018

Severity High
Score 7.1/10

Summary

Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0 through 9.5.54, 10.0.0 through 10.4.53, 11.0.0 through 11.5.47, 12.0.0 through 12.4.36, and 13.0.0 through 13.4.17 allow backend users to directly invoke the corresponding AJAX backend route to disclose sensitive information without having access.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • LOW
  • HIGH
  • NONE

CWE-200 - Information Exposure

An information exposure vulnerability is categorized as an information flow (IF) weakness, which can potentially allow unauthorized access to otherwise classified information in the application, such as confidential personal information (demographics, financials, health records, etc.), business secrets, and the application's internal environment.

Advisory Timeline

  • Published