Vulnerability identifier: #VU109604
Vulnerability risk: Low
CVSSv4.0: 6.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID:
CWE-ID:
CWE-283
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
TYPO3
Web applications /
CMS
Vendor: TYPO3
Description
The vulnerability allows a remote user to compromise the target system.
The vulnerability exists due to the unverified ownership issue. A remote administrator can gain elevated privileges on the system.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
TYPO3: 10.4.0, 10.4.1 - 13.4.11, 10.4.2, 10.4.3 - 10.4.39, 10.4.4 - 10.4.49, 10.4.5, 10.4.6 - 11.5.10, 10.4.7 - 11.5.20, 10.4.8 - 11.5.30, 10.4.9, 10.4.10 - 12.3.0, 10.4.11 - 12.4.9, 10.4.20, 10.4.21, 10.4.22, 10.4.23, 10.4.24, 10.4.25, 10.4.26, 10.4.27, 10.4.28, 10.4.29, 11.0.0, 11.1.0, 11.1.1, 11.2.0, 11.3.0, 11.3.1, 11.3.2, 11.3.3, 11.4.0, 11.5.0, 11.5.31, 11.5.32, 11.5.33, 11.5.34, 11.5.35, 11.5.36, 11.5.37, 11.5.38, 11.5.39, 11.5.40
External links
https://github.com/TYPO3/typo3/security/advisories/GHSA-6frx-j292-c844
https://typo3.org/security/advisory/typo3-core-sa-2025-016
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.