CVE-2025-48204: OS Command Injection
Published May 21, 2025
·Updated
The nsbackup extension through 13.0.0 for TYPO3 allows command injection when creating a backup. An authenticated backend user with access to the extensions backend module is required to exploit the vulnerability.
Affected Software
2 affected componentsFixes available
Typo3 ns_backup<13.0.0
composer/nitsan/ns-backup<13.0.1
13.0.1
Event History
May 21, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·06:33 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-48204?
CVE-2025-48204 has a high severity rating due to its potential for command injection.
2
How do I fix CVE-2025-48204?
To fix CVE-2025-48204, update the ns_backup extension to version 13.0.0 or higher.
3
What systems are affected by CVE-2025-48204?
CVE-2025-48204 affects versions of the ns_backup extension prior to 13.0.0.
4
Is CVE-2025-48204 being actively exploited?
Currently, there is no public information indicating that CVE-2025-48204 is actively being exploited in the wild.
5
What are the potential impacts of CVE-2025-48204 on my system?
The potential impacts of CVE-2025-48204 include unauthorized command execution, which could compromise system security.