Database Query Vulnerability in TYPO3 by TYPO3
CVE-2025-47937

3.7LOW

Key Information:

Vendor

Typo3

Status
Vendor
CVE Published:
20 May 2025

What is CVE-2025-47937?

TYPO3, an open-source PHP-based web content management system, has a vulnerability in its database abstraction layer (DBAL). This issue affects versions 9.0.0 to prior versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS. In scenarios involving database queries across multiple tables, frontend user permissions, specifically applied via FrontendGroupRestriction, only restrict access to the first table. Consequently, data from additional tables may be inadvertently exposed to unauthorized users. It is recommended that users update to the latest versions to mitigate this risk.

Affected Version(s)

typo3 >= 9.0.0, < 9.5.51 < 9.0.0, 9.5.51

typo3 >= 10.0.0, < 10.4.50 < 10.0.0, 10.4.50

typo3 >= 11.0.0, < 11.5.44 < 11.0.0, 11.5.44

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-47937 : Database Query Vulnerability in TYPO3 by TYPO3