CVE-2025-48201: High severity typo3 ns_backup vulnerability
Published May 21, 2025
·Updated
The nsbackup extension through 13.0.0 for TYPO3 has a Predictable Resource Location.
Affected Software
2 affected componentsFixes available
Typo3 ns_backup<=13.0.0
composer/nitsan/ns-backup<13.0.1
13.0.1
Event History
May 21, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·07:51 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-48201?
The severity of CVE-2025-48201 has not been officially rated, but it poses a significant risk due to its predictable resource location feature.
2
How do I fix CVE-2025-48201?
To fix CVE-2025-48201, upgrade the TYPO3 ns_backup extension to a version higher than 13.0.0.
3
What systems are affected by CVE-2025-48201?
CVE-2025-48201 affects the TYPO3 ns_backup extension versions up to and including 13.0.0.
4
What issues does CVE-2025-48201 lead to?
CVE-2025-48201 can lead to unauthorized access to resources due to its predictable resource location flaw.
5
Is there a patch available for CVE-2025-48201?
A patch is typically released with new versions of the software, so updating to a version above 13.0.0 addresses CVE-2025-48201.