CVE-2020-11069
published 2026-08-11CVE-2020-11069: The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend…
PriorityP338high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.71%
51.2th percentile
The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend and Install Tool applications from the site's main entry script instead of the dedicated typo3/ directory.
Whether a request originated from the backend or Install Tool itself was determined by comparing the referrer against the directory of the entry script, which since then is the site root. As a consequence, requests originating from any script running on one of the TYPO3 instance's own domains, such as a frontend page, were accepted by backend routes and Install Tool endpoints.
Attackers able to execute JavaScript on one of those domains, for instance by exploiting a cross-site scripting vulnerability, could invoke these endpoints via Fetch/XHR with the privileges of an authenticated victim's user session. This issue affects TYPO3 CMS versions 13.0.0-13.4.33 and 14.0.0-14.3.5.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| typo3 | cms | >= 10.0.0 < 10.4.2 | 10.4.2 |
| typo3 | cms | >= 11.2.0 < 11.5.0 | 11.5.0 |
| typo3 | cms | >= 9.0.0 < 9.5.17 | 9.5.17 |
| typo3 | cms-backend | >= 13.0.0 < 13.4.34 | 13.4.34 |
| typo3 | cms-core | >= 10.0.0 < 10.4.2 | 10.4.2 |
| typo3 | cms-core | >= 11.2.0 < 11.5.0 | 11.5.0 |
| typo3 | cms-core | >= 13.0.0 < 13.4.34 | 13.4.34 |
| typo3 | cms-core | >= 14.0.0 < 14.3.6 | 14.3.6 |
| typo3 | cms-core | >= 9.0.0 < 9.5.17 | 9.5.17 |
| typo3 | typo3 | 10.0.0 – 10.4.1 | — |
| typo3 | typo3 | >= 11.2.0 < 11.5.0 | 11.5.0 |
| typo3 | typo3 | 9.0.0 – 9.5.16 | — |
| typo3 | typo3_cms | >= 13.0.0 < 13.4.34 | 13.4.34 |
| typo3 | typo3_cms | >= 14.0.0 < 14.3.6 | 14.3.6 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
ghsa8.8HIGH
osv8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
TYPO3 CMS - Broken Access Control in Backend and Install Tool
ghsa·2026-09-01·CVSS 8.8
CVE-2026-19418 [HIGH] CWE-346 TYPO3 CMS - Broken Access Control in Backend and Install Tool
TYPO3 CMS - Broken Access Control in Backend and Install Tool
### Problem
The referrer enforcement introduced with [TYPO3-CORE-SA-2020-006](https://news.typo3.com/security/advisory/typo3-core-sa-2020-006) ([CVE-2020-11069](https://www.cve.org/CVERecord?id=CVE-2020-11069)) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend and Admin Tool applications from the site's main entry script instead of the dedicated typo3/ directory.
Whether a request originated from the backend or Install Tool itself was determined by comparing the referrer against the directory of the entry script, which since then is the site root. As a consequence, requests originating from any script running on one of the TYPO3 instance's own domains, such as a frontend page, were accepted by back
GHSA
Duplicate Advisory: TYPO3-CORE-SA-2026-021: Broken Access Control in Backend and Install Tool
ghsa·2026-08-11·CVSS 8.8
CVE-2020-11069 [HIGH] CWE-346 Duplicate Advisory: TYPO3-CORE-SA-2026-021: Broken Access Control in Backend and Install Tool
Duplicate Advisory: TYPO3-CORE-SA-2026-021: Broken Access Control in Backend and Install Tool
## Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-68jx-f42c-7599. This link is maintained to preserve external references.
## Original Description
The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend and Install Tool applications from the site's main entry script instead of the dedicated typo3/ directory.
Whether a request originated from the backend or Install Tool itself was determined by comparing the referrer against the directory of the entry script, which since then is the site root. As a consequence, requests originating from any script runnin
GHSA
The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend and Install Tool applications from the s
ghsa_unreviewed·2026-08-11·CVSS 8.8
CVE-2026-19418 [HIGH] CWE-346 The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend and Install Tool applications from the s
The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend and Install Tool applications from the site's main entry script instead of the dedicated typo3/ directory.
Whether a request originated from the backend or Install Tool itself was determined by comparing the referrer against the directory of the entry script, which since then is the site root. As a consequence, requests originating from any script running on one of the TYPO3 instance's own domains, such as a frontend page, were accepted by backend routes and Install Tool endpoints.
Attackers able to execute JavaScript on one of those domains, for instance by exploiting a cross-site scripting vulnerability, could invoke these endpo
OSV
Cross-Site-Request-Forgery in Backend
osv·2021-10-05·CVSS 8.8
CVE-2021-41113 [HIGH] Cross-Site-Request-Forgery in Backend
Cross-Site-Request-Forgery in Backend
> ### Meta
> * CVSS: `CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C` (8.2)
### Problem
It has been discovered that the new TYPO3 v11 feature that allows users to create and share [deep links in the backend user interface](https://typo3.org/article/typo3-version-112-escape-the-orbit#c12178) is vulnerable to cross-site-request-forgery.
The impact is the same as described in [TYPO3-CORE-SA-2020-006 (CVE-2020-11069)](https://typo3.org/security/advisory/typo3-core-sa-2020-006). However, it is not limited to the same site context and does not require the attacker to be authenticated. In a worst case scenario, the attacker could create a new admin user account to compromise the system.
To successfully carry out an attack, an attacker must tri
GHSA
Cross-Site-Request-Forgery in Backend
ghsa·2021-10-05·CVSS 8.8
CVE-2021-41113 [HIGH] CWE-309 Cross-Site-Request-Forgery in Backend
Cross-Site-Request-Forgery in Backend
> ### Meta
> * CVSS: `CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C` (8.2)
### Problem
It has been discovered that the new TYPO3 v11 feature that allows users to create and share [deep links in the backend user interface](https://typo3.org/article/typo3-version-112-escape-the-orbit#c12178) is vulnerable to cross-site-request-forgery.
The impact is the same as described in [TYPO3-CORE-SA-2020-006 (CVE-2020-11069)](https://typo3.org/security/advisory/typo3-core-sa-2020-006). However, it is not limited to the same site context and does not require the attacker to be authenticated. In a worst case scenario, the attacker could create a new admin user account to compromise the system.
To successfully carry out an attack, an attacker must tri
OSV
Backend Same-Site Request Forgery in TYPO3 CMS
osv·2020-05-13
CVE-2020-11069 [HIGH] Backend Same-Site Request Forgery in TYPO3 CMS
Backend Same-Site Request Forgery in TYPO3 CMS
> ### Meta
> * CVSS v3.1: AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
> * CWE-352
> * CWE-346
### Problem
It has been discovered that backend user interface and install tool are vulnerable to same-origin request forgery. A backend user can be tricked into interacting with a malicious resource an attacker previously managed to upload to the web server - scripts are then executed with the privileges of the victims' user session.
In a worst case scenario new admin users can be created which can directly be used by an attacker. The vulnerability is basically a cross-site request forgery (CSRF) triggered by a cross-site scripting vulnerability (XSS) - but happens on the same target host - thus, it’s actually a same-origin request forgery.
GHSA
Backend Same-Site Request Forgery in TYPO3 CMS
ghsa·2020-05-13
CVE-2020-11069 [HIGH] CWE-346 Backend Same-Site Request Forgery in TYPO3 CMS
Backend Same-Site Request Forgery in TYPO3 CMS
> ### Meta
> * CVSS v3.1: AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
> * CWE-352
> * CWE-346
### Problem
It has been discovered that backend user interface and install tool are vulnerable to same-origin request forgery. A backend user can be tricked into interacting with a malicious resource an attacker previously managed to upload to the web server - scripts are then executed with the privileges of the victims' user session.
In a worst case scenario new admin users can be created which can directly be used by an attacker. The vulnerability is basically a cross-site request forgery (CSRF) triggered by a cross-site scripting vulnerability (XSS) - but happens on the same target host - thus, it’s actually a same-origin request forgery.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/TYPO3/typo3/commit/4a75e862c589c85d795d7c65dcdc835f8f413efchttps://github.com/TYPO3/typo3/commit/a0e8ee06a40e959b9e7b06a4b1cb19d3a0d3dcf7https://github.com/TYPO3/typo3/commit/ae0abd329d52285fe6e92804c3608820ad45e872https://typo3.org/security/advisory/typo3-core-sa-2020-006https://typo3.org/security/advisory/typo3-core-sa-2026-021
2026-08-11
Published