Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-59019


Missing authorization checks in the CSV download feature of TYPO3 CMS versions 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to disclose information from arbitrary database tables stored within the users' web mounts without having access to them.


Published

2025-09-09T09:15:41.113

Last Modified

2025-09-26T14:09:51.020

Status

Analyzed

Source

f4fb688c-4412-4426-b4b8-421ecf27b14a

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application typo3 typo3 < 11.5.48 Yes
Application typo3 typo3 < 12.4.37 Yes
Application typo3 typo3 < 13.4.18 Yes

References