CyberRota Analysis
AI-GeneratedSeveral versions of TYPO3 CMS are vulnerable due to insufficient authorization checks in AJAX routes used for the backend localization wizard, allowing low-privileged authenticated users to access unauthorized records and content elements. This could lead to unauthorized information disclosure within the system. Organizations using affected TYPO3 versions should prioritize remediation to mitigate the risk of data exposure from compromised low-privileged accounts.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged backend users to access information about records and content elements that fall outside of their permitted range. Exploiting this vulnerability requires a low-privileged backend user account. This issue affects TYPO3 CMS versions 10.0.0-10.4.59, 11.0.0-11.5.53, 12.0.0-12.4.48, 13.0.0-13.4.34 and 14.0.0-14.3.6.