TYPO3 CMS
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*
- >= 10.0.0, <= 10.4.47
- >= 11.0.0, <= 11.5.41
- >= 12.0.0, <= 12.4.24
- >= 13.0.0, <= 13.4.2
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the TYPO3 backend user interface, specifically within the Dashboard Module. This issue arises from deep link functionality that improperly accepts state-changing actions via HTTP GET, lacking the necessary enforcement of correct HTTP methods. Exploitation requires the victim to have an active backend session and to be misled into clicking a malicious link, particularly under conditions where the 'security.backend.enforceReferrer' feature is turned off and the 'BE/cookieSameSite' setting is lax or absent.
Exploitation allows attackers to manipulate the victim's dashboard configuration within TYPO3.
Users are advised to update TYPO3 to versions 11.5.42 ELTS, 12.4.25 LTS, or 13.4.3 LTS. Extension authors should review and update their codebases accordingly.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.