Improper Authentication Vulnerability in TYPO3 Extension Modules by TYPO3
CVE-2025-12998

8.2HIGH

Key Information:

Vendor

Typo3

Vendor
CVE Published:
12 November 2025

What is CVE-2025-12998?

The TYPO3 Extension 'Modules' suffers from an improper authentication vulnerability that allows unauthorized access to certain functionalities. This issue affects multiple versions of the extension, including those prior to 4.3.11 and various ranges from versions 5.0.0 to 7.5.5. It is crucial for users and administrators to update their installations to the latest versions to mitigate the risks associated with this vulnerability.

Affected Version(s)

Extension "Modules" 0 < 4.3.11

Extension "Modules" 5.0.0 < 5.7.4

Extension "Modules" 6.0.0 < 6.4.2

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thomas Deuling
.
CVE-2025-12998 : Improper Authentication Vulnerability in TYPO3 Extension Modules by TYPO3