MEDIUM
GHSA-2fhw-2j7m-mr4m
TYPO3 backend modules have Broken Access Control
Quick fix
GHSA-2fhw-2j7m-mr4m — typo3/cms-workspaces: upgrade to the fixed version with the command below.
composer require typo3/cms-workspaces:^12.4.37Details
Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend routes without having access to the corresponding backend modules.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/typo3/cms-workspaces
Introduced in:
9.0.0Fixed in: 12.4.37Fix
composer require typo3/cms-workspaces:^12.4.37Packagist/typo3/cms-workspaces
Introduced in:
10.0.0Fixed in: 12.4.37Fix
composer require typo3/cms-workspaces:^12.4.37Packagist/typo3/cms-workspaces
Introduced in:
11.0.0Fixed in: 12.4.37Fix
composer require typo3/cms-workspaces:^12.4.37Packagist/typo3/cms-workspaces
Introduced in:
12.0.0Fixed in: 12.4.37Fix
composer require typo3/cms-workspaces:^12.4.37Packagist/typo3/cms-workspaces
Introduced in:
13.0.0Fixed in: 13.4.18Fix
composer require typo3/cms-workspaces:^13.4.18Packagist/typo3/cms-recycler
Introduced in:
9.0.0Fixed in: 12.4.37Fix
composer require typo3/cms-recycler:^12.4.37Packagist/typo3/cms-recycler
Introduced in:
10.0.0Fixed in: 12.4.37Fix
composer require typo3/cms-recycler:^12.4.37Packagist/typo3/cms-recycler
Introduced in:
11.0.0Fixed in: 12.4.37Fix
composer require typo3/cms-recycler:^12.4.37Packagist/typo3/cms-recycler
Introduced in:
12.0.0Fixed in: 12.4.37Fix
composer require typo3/cms-recycler:^12.4.37Packagist/typo3/cms-recycler
Introduced in:
13.0.0Fixed in: 13.4.18Fix
composer require typo3/cms-recycler:^13.4.18Packagist/typo3/cms-dashboard
Introduced in:
10.0.0Fixed in: 12.4.37Fix
composer require typo3/cms-dashboard:^12.4.37Packagist/typo3/cms-dashboard
Introduced in:
11.0.0Fixed in: 12.4.37Fix
composer require typo3/cms-dashboard:^12.4.37Packagist/typo3/cms-dashboard
Introduced in:
12.0.0Fixed in: 12.4.37Fix
composer require typo3/cms-dashboard:^12.4.37Packagist/typo3/cms-dashboard
Introduced in:
13.0.0Fixed in: 13.4.18Fix
composer require typo3/cms-dashboard:^13.4.18Packagist/typo3/cms-beuser
Introduced in:
13.0.0Fixed in: 13.4.18Fix
composer require typo3/cms-beuser:^13.4.18Packagist/typo3/cms-beuser
Introduced in:
12.0.0Fixed in: 12.4.37Fix
composer require typo3/cms-beuser:^12.4.37Packagist/typo3/cms-beuser
Introduced in:
11.0.0Fixed in: 12.4.37Fix
composer require typo3/cms-beuser:^12.4.37Packagist/typo3/cms-beuser
Introduced in:
10.0.0Fixed in: 12.4.37Fix
composer require typo3/cms-beuser:^12.4.37Packagist/typo3/cms-beuser
Introduced in:
9.0.0Fixed in: 12.4.37Fix
composer require typo3/cms-beuser:^12.4.37Packagist/typo3/cms-backend
Introduced in:
9.0.0Fixed in: 12.4.37Fix
composer require typo3/cms-backend:^12.4.37Packagist/typo3/cms-backend
Introduced in:
10.0.0Fixed in: 12.4.37Fix
composer require typo3/cms-backend:^12.4.37Packagist/typo3/cms-backend
Introduced in:
11.0.0Fixed in: 12.4.37Fix
composer require typo3/cms-backend:^12.4.37Packagist/typo3/cms-backend
Introduced in:
12.0.0Fixed in: 12.4.37Fix
composer require typo3/cms-backend:^12.4.37Packagist/typo3/cms-backend
Introduced in:
13.0.0Fixed in: 13.4.18Fix
composer require typo3/cms-backend:^13.4.18References
- https://nvd.nist.gov/vuln/detail/CVE-2025-59017[ADVISORY]
- https://github.com/TYPO3-CMS/backend/commit/0aedf33d910bceafc2ed0e715743cc0d30124501[WEB]
- https://github.com/TYPO3-CMS/beuser/commit/eb9b0c14a514a7aada8a2aa30e57696e286044c7[WEB]
- https://github.com/TYPO3-CMS/dashboard/commit/582006c6bdf251160001eee6624901baccdcfcd2[WEB]
- https://github.com/TYPO3-CMS/recycler/commit/43475578eb1d9fa3b765537c96bcdf48582ee53b[WEB]
- https://github.com/TYPO3-CMS/workspaces/commit/32222508043940f9073c338d4205c730a2e02070[WEB]
- https://typo3.org/security/advisory/typo3-core-sa-2025-021[WEB]