CVE-2025-59015Insufficient Entropy in CMS

Severity
6.3MEDIUMNVD
EPSS
0.0%
top 89.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 9

Description

A deterministic three‑character prefix in the Password Generation component of TYPO3 CMS versions 12.0.0–12.4.36 and 13.0.0–13.4.17 reduces entropy, allowing attackers to carry out brute‑force attacks more quickly.

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Packages3 packages

NVDtypo3/typo312.0.012.4.37+1
Packagisttypo3/cms-core12.0.012.4.37+1
CVEListV5typo3/typo3_cms12.0.012.4.37+1

🔴Vulnerability Details

3
GHSA
TYPO3 CMS uses insufficient entropy when generating passwords2025-09-09
OSV
TYPO3 CMS uses insufficient entropy when generating passwords2025-09-09
CVEList
Insufficient Entropy in Password Generation2025-09-09
CVE-2025-59015 — Insufficient Entropy in Typo3 CMS | cvebase