CVE-2025-59018Sensitive Information Exposure in CMS

Severity
7.1HIGHNVD
EPSS
0.1%
top 84.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 9

Description

Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke the corresponding AJAX backend route to disclose sensitive information without having access.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Packages3 packages

Packagisttypo3/cms-workspaces9.0.012.4.37+4
NVDtypo3/typo39.0.09.5.55+4
CVEListV5typo3/typo3_cms9.0.09.5.55+4

🔴Vulnerability Details

3
OSV
TYPO3 Workspaces Module Information Disclosure2025-09-09
GHSA
TYPO3 Workspaces Module Information Disclosure2025-09-09
CVEList
Information Disclosure in Workspaces Module2025-09-09
CVE-2025-59018 — Sensitive Information Exposure in CMS | cvebase