Cross-Site Request Forgery Vulnerability in TYPO3 CMS Backend Interface
CVE-2024-55923
What is CVE-2024-55923?
A vulnerability has been identified in TYPO3 CMS that exposes the backend user interface to Cross-Site Request Forgery (CSRF) attacks. This issue arises from the way deep links are handled, allowing malicious actors to exploit state-changing actions in the Indexed Search Module. Specifically, when the 'security.backend.enforceReferrer' setting is disabled and the 'BE/cookieSameSite' configuration is set incorrectly, attackers can manipulate the system to accept submissions via HTTP GET instead of the required HTTP methods. For successful exploitation, victims need to be tricked into interacting with a malicious URL while logged into the backend interface. TYPO3 recommends updating to versions 11.5.42 ELTS, 12.4.25 LTS, or 13.4.3 LTS to mitigate this risk.
Affected Version(s)
typo3 >= 10.0.0, < 10.4.48 < 10.0.0, 10.4.48
typo3 >= 11.0.0, < 11.5.42 < 11.0.0, 11.5.42
typo3 >= 12.0.0, < 12.4.25 < 12.0.0, 12.4.25
References
CVSS V3.1
Timeline
Vulnerability published