Security Flaw in TYPO3 CMS Allows Unauthorized Redirect Manipulation
CVE-2025-59021
5.3MEDIUM
What is CVE-2025-59021?
A security issue in TYPO3 CMS allows backend users with access to the redirects module and write permissions to the sys_redirect table to manipulate redirect records. This vulnerability enables attackers to create, read, and modify redirects without restrictions, leading to the potential for phishing attacks or redirections to malicious sites. It impacts multiple versions of TYPO3 CMS, which makes it crucial for users to upgrade to the latest patched versions.
Affected Version(s)
TYPO3 CMS 10.0.0 < 10.4.55
TYPO3 CMS 11.0.0 < 11.5.49
TYPO3 CMS 12.0.0 < 12.4.41
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Georg DĂĽmmler
Elias Häußler
