TYPO3 Cross-Site Request Forgery Vulnerability in Indexed Search Module

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in TYPO3's backend user interface, specifically within the Indexed Search Module. This issue arises because deep link functionality does not properly enforce HTTP method requirements, allowing state-changing actions to be submitted via HTTP GET. Exploitation requires the victim to have an active backend session and to be tricked into clicking a malicious link, particularly under certain misconfigured settings. When successfully exploited, attackers can delete items within the Indexed Search component.

Impact

Exploitation of this vulnerability allows for Cross-Site Request Forgery, enabling attackers to perform actions on behalf of the victim user, specifically deleting items in the Indexed Search Module.

Remediation

Users are advised to update TYPO3 to versions 11.5.42 ELTS, 12.4.25 LTS, or 13.4.3 LTS. Extension authors should review and update their codebases accordingly.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
0.6
exploitability
6.5
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.