TYPO3 CMS
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*
- >= 9.0.0, <= 9.5.54
- >= 10.0.0, <= 10.4.53
- >= 11.0.0, <= 11.5.47
- >= 12.0.0, <= 12.4.36
- >= 13.0.0, <= 13.4.17
A broken access control vulnerability has been identified in the Workspace Module of TYPO3 CMS. This issue affects versions 9.0.0 through 9.5.54, 10.0.0 through 10.4.53, 11.0.0 through 11.5.47, 12.0.0 through 12.4.36, and 13.0.0 through 13.4.17. The vulnerability arises from missing authorization checks in dedicated AJAX routes used by TYPO3 backend modules. As a result, authenticated backend users can directly invoke these routes without the necessary permissions, potentially leading to unauthorized disclosure, modification, or deletion of sensitive information.
Exploitation of this vulnerability allows authenticated backend users to bypass module-level access controls, directly invoking AJAX routes to read, modify, or delete data without proper authorization.
Users are advised to update TYPO3 to versions 9.5.55 ELTS, 10.4.54 ELTS, 11.5.48 ELTS, 12.4.37 LTS, or 13.4.18 LTS. These versions include the necessary access controls for AJAX routes, ensuring they inherit permissions from the corresponding backend modules.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.