CVE-2024-55921: Cross-Site Request Forgery in Extension Manager Module in TYPO3

Published Jan 14, 2025
·
Updated

Problem A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing actions in downstream components incorrectly accepted submissions via HTTP GET and did not enforce the appropriate HTTP method.

Successful exploitation of this vulnerability requires the victim to have an active session on the backend user interface and to be deceived into interacting with a malicious URL targeting the backend, which can occur under the following conditions:

the user opens a malicious link, such as one sent via email. the user visits a compromised or manipulated website while the following settings are misconfigured: + security.backend.enforceReferrer feature is disabled, + BE/cookieSameSite configuration is set to lax or none

The vulnerability in the affected downstream component “Extension Manager Module” allows attackers to retrieve and install 3rd party extensions from the TYPO3 Extension Repository - which can lead to remote code execution in the worst case.

Solution Update to TYPO3 versions 11.5.42 ELTS, 12.4.25 LTS, 13.4.3 LTS that fix the problem described.

Credits Thanks to TYPO3 core and security members Benjamin Franzke, Oliver Hader, Andreas Kienast, Torben Hansen, Elias Häußler who fixed the issue.

References TYPO3-CORE-SA-2025-006

Other sources

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing actions in downstream components incorrectly accepted submissions via HTTP GET and did not enforce the appropriate HTTP method. Successful exploitation of this vulnerability requires the victim to have an active session on the backend user interface and to be deceived into interacting with a malicious URL targeting the backend, which can occur under the following conditions: The user opens a malicious link, such as one sent via email. The user visits a compromised or manipulated website while the following settings are misconfigured: 1. security.backend.enforceReferrer feature is disabled, 2. BE/cookieSameSite configuration is set to lax or none. The vulnerability in the affected downstream component “Extension Manager Module” allows attackers to retrieve and install 3rd party extensions from the TYPO3 Extension Repository - which can lead to remote code execution in the worst case. Users are advised to update to TYPO3 versions 11.5.42 ELTS, 12.4.25 LTS, 13.4.3 LTS which fix the problem described.

NVD

Affected Software

8 affected componentsFixes available
composer/typo3/cms-extensionmanager>=13.0.0<=13.4.2
13.4.3
composer/typo3/cms-extensionmanager>=12.0.0<=12.4.24
12.4.25
composer/typo3/cms-extensionmanager>=11.0.0<=11.5.41
11.5.42
composer/typo3/cms-extensionmanager>=10.0.0<=10.4.47
10.4.48
Typo3 TYPO3>=10.0.0<10.4.48
Typo3 TYPO3>=11.0.0<11.5.42
Typo3 TYPO3>=12.0.0<12.4.25
Typo3 TYPO3>=13.0.0<13.4.3

Event History

Jan 14, 2025
Advisory Published
via GitHub·03:40 PM
CVE Published
via MITRE·07:36 PM
Data Sourced
via MITRE·07:36 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
Affected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-55921?

CVE-2024-55921 is classified as a moderate severity vulnerability due to its potential for exploitation through Cross-Site Request Forgery (CSRF).

2

How do I fix CVE-2024-55921?

To resolve CVE-2024-55921, upgrade the TYPO3 cms-extensionmanager to versions 13.4.3, 12.4.25, 11.5.42, or 10.4.48 depending on your current version.

3

Which versions of TYPO3 are affected by CVE-2024-55921?

CVE-2024-55921 affects TYPO3 versions from 10.0.0 to 10.4.47, 11.0.0 to 11.5.41, 12.0.0 to 12.4.24, and 13.0.0 to 13.4.2.

4

What type of attack does CVE-2024-55921 enable?

CVE-2024-55921 enables Cross-Site Request Forgery (CSRF) attacks that can lead to unauthorized state-changing actions in downstream components.

5

What components are affected by CVE-2024-55921?

CVE-2024-55921 specifically affects the backend user interface functionality of the TYPO3 cms-extensionmanager.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203