TYPO3 CMS
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*
- >= 9.0.0, <= 9.5.54
- >= 10.0.0, <= 10.4.53
- >= 11.0.0, <= 11.5.47
- >= 12.0.0, <= 12.4.36
- >= 13.0.0, <= 13.4.17
A vulnerability allowing unauthorized information disclosure has been identified in the Workspaces Module of TYPO3 CMS. This issue affects versions 11.0.0 through 11.5.47, 12.0.0 through 12.4.36, and 13.0.0 through 13.4.17. The vulnerability arises from missing authorization checks in the CSV download feature, which allows backend users to access data from arbitrary database tables within their web mounts, even if they do not have the necessary permissions.
Exploitation of this vulnerability could lead to unauthorized access to sensitive information from database tables that the user does not have rights to, allowing for potential privacy breaches or misuse of data.
Users are advised to update TYPO3 to versions 11.5.48 ELTS, 12.4.37 LTS, or 13.4.18 LTS, which address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.