Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke the corresponding AJAX backend route to disclose sensitive information without having access.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-27227 Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke the corresponding AJAX backend route to disclose sensitive information without having access.
Github GHSA Github GHSA GHSA-w2pf-7q5w-2cgw TYPO3 Workspaces Module Information Disclosure
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 12 Sep 2025 06:30:00 +0900


Fri, 12 Sep 2025 05:45:00 +0900

Type Values Removed Values Added
References

Wed, 10 Sep 2025 23:00:00 +0900

Type Values Removed Values Added
CPEs cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Wed, 10 Sep 2025 08:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 10 Sep 2025 06:45:00 +0900

Type Values Removed Values Added
First Time appeared Typo3
Typo3 typo3
Vendors & Products Typo3
Typo3 typo3

Tue, 09 Sep 2025 18:15:00 +0900

Type Values Removed Values Added
Description Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke the corresponding AJAX backend route to disclose sensitive information without having access.
Title Information Disclosure in Workspaces Module
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: TYPO3

Published:

Updated: 2025-09-11T20:35:36.245Z

Reserved: 2025-09-07T19:01:20.436Z

Link: CVE-2025-59018

cve-icon Vulnrichment

Updated: 2025-09-09T19:29:50.296Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-09T09:15:40.907

Modified: 2025-09-26T14:08:37.780

Link: CVE-2025-59018

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-10T06:31:33Z

Weaknesses