Missing Authorization Checks in TYPO3 CMS Backend Routing
CVE-2025-59017
5.3MEDIUM
What is CVE-2025-59017?
A lack of proper authorization checks in the Backend Routing of various TYPO3 CMS versions enables backend users to access AJAX routes directly, circumventing access controls associated with the relevant backend modules. This could potentially allow unauthorized users to execute operations they shouldn’t have access to, posing a significant security risk.
Affected Version(s)
TYPO3 CMS 9.0.0 < 9.5.55
TYPO3 CMS 10.0.0 < 10.4.54
TYPO3 CMS 11.0.0 < 11.5.48
