HIGH8.6
GHSA-hq4f-5qjv-fwrg
The Backup Plus extension for TYPO3 (ns_backup) has a Predictable Resource Location
Quick fix
GHSA-hq4f-5qjv-fwrg — nitsan/ns-backup: upgrade to the fixed version with the command below.
composer require nitsan/ns-backup:^13.0.1Details
The ns_backup extension through 13.0.0 for TYPO3 has a Predictable Resource Location. This allows an unauthenticated remote user to download created backups and configuration files.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/nitsan/ns-backup
Introduced in:
0Fixed in: 13.0.1Fix
composer require nitsan/ns-backup:^13.0.1References
- https://nvd.nist.gov/vuln/detail/CVE-2025-48201[ADVISORY]
- https://github.com/nitsan-technologies/ns_backup/commit/67b8102a19e8e516dc4228f5c42f9e4fba5046cb[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/nitsan/ns-backup/CVE-2025-48201.yaml[WEB]
- https://github.com/nitsan-technologies/ns_backup[PACKAGE]
- https://typo3.org/security/advisory/typo3-ext-sa-2025-007[WEB]