HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2025-47940

CVSS 7.2v3.1pub. 2025-05-20upd. 2025-09-03

TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to versions 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, administrator-level backend users without system maintainer privileges can escalate their privileges and gain system maintainer access. Exploiting this vulnerability requires a valid administrator account. Users should update to TYPO3 version 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, or 13.4.12 LTS to fix the problem.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Typo3

    APP
    Typo3
    10.4.0 – 10.4.50 (excl.)11.0.0 – 11.5.44 (excl.)12.0.0 – 12.4.31 (excl.)13.0.0 – 13.4.12 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2011-3583CRITICAL9.8PL ✓same product

SQL Injection w TYPO3 Core przez niepoprawne prepared statements

CVE-2011-4628CRITICAL9.8PL ✓same product

TYPO3: Ominięcie mechanizmu uwierzytelniania w panelu administracyjnym

CVE-2026-6553HIGH7.3same product

Changing backend users' passwords via the user settings module results in storing the cleartext password in th...

CVE-2025-59022HIGH7.1same product

Backend users who had access to the recycler module could delete arbitrary data from any database table define...

CVE-2025-59018HIGH7.1same product

Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0....