Cross-Site Request Forgery Vulnerability in TYPO3 CMS Backend Interface
CVE-2024-55923

4.3MEDIUM

Key Information:

Vendor

Typo3

Status
Vendor
CVE Published:
14 January 2025

What is CVE-2024-55923?

A vulnerability has been identified in TYPO3 CMS that exposes the backend user interface to Cross-Site Request Forgery (CSRF) attacks. This issue arises from the way deep links are handled, allowing malicious actors to exploit state-changing actions in the Indexed Search Module. Specifically, when the 'security.backend.enforceReferrer' setting is disabled and the 'BE/cookieSameSite' configuration is set incorrectly, attackers can manipulate the system to accept submissions via HTTP GET instead of the required HTTP methods. For successful exploitation, victims need to be tricked into interacting with a malicious URL while logged into the backend interface. TYPO3 recommends updating to versions 11.5.42 ELTS, 12.4.25 LTS, or 13.4.3 LTS to mitigate this risk.

Affected Version(s)

typo3 >= 10.0.0, < 10.4.48 < 10.0.0, 10.4.48

typo3 >= 11.0.0, < 11.5.42 < 11.0.0, 11.5.42

typo3 >= 12.0.0, < 12.4.25 < 12.0.0, 12.4.25

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.