CVE-2025-59019: Information Disclosure via CSV Download
Missing authorization checks in the CSV download feature of TYPO3 CMS versions 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to disclose information from arbitrary database tables stored within the users' web mounts without having access to them.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59019?
CVE-2025-59019 is considered a high severity vulnerability due to the potential for unauthorized data disclosure.
How do I fix CVE-2025-59019?
To fix CVE-2025-59019, update your TYPO3 CMS to versions 11.5.48 or later, 12.4.37 or later, or 13.4.18 or later.
Who is affected by CVE-2025-59019?
CVE-2025-59019 affects backend users of TYPO3 CMS versions 11.0.0 to 11.5.47, 12.0.0 to 12.4.36, and 13.0.0 to 13.4.17.
What type of information can be disclosed due to CVE-2025-59019?
CVE-2025-59019 allows disclosure of information from arbitrary database tables accessible through the users' web mounts.
Is there a workaround for CVE-2025-59019 while awaiting a fix?
There are no official workarounds for CVE-2025-59019; updating to a secure version is recommended as the primary mitigation.