CVE-2025-59017: Broken Access Control in Backend AJAX Routes
Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend routes without having access to the corresponding backend modules.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59017?
CVE-2025-59017 has a medium severity rating due to missing authorization checks in the backend routing.
How do I fix CVE-2025-59017?
To fix CVE-2025-59017, you should upgrade TYPO3 CMS to a version that is not affected by this vulnerability.
Which versions of TYPO3 CMS are vulnerable to CVE-2025-59017?
CVE-2025-59017 affects TYPO3 CMS versions 9.0.0 to 9.5.54, 10.0.0 to 10.4.53, 11.0.0 to 11.5.47, 12.0.0 to 12.4.36, and 13.0.0 to 13.4.17.
What type of attack does CVE-2025-59017 enable?
CVE-2025-59017 enables unauthorized backend users to invoke AJAX backend routes without appropriate access.
Is my system safe if I am using a patched version of TYPO3 CMS regarding CVE-2025-59017?
Yes, if you are using a patched version of TYPO3 CMS, your system is safe from the vulnerabilities associated with CVE-2025-59017.