CVE-2025-59021: TYPO3 CMS Allows Broken Access Control in Redirects Module
Problem Backend users with access to the redirects module and write permission on the sysredirect table were able to read, create, and modify any redirect record - without restriction to the user’s own file‑mounts or web‑mounts. This allowed attackers to insert or alter redirects pointing to arbitrary URLs - facilitating phishing or other malicious redirect attacks.
Solution Update to TYPO3 versions 10.4.55 ELTS, 11.5.49 ELTS, 12.4.41 LTS, 13.4.23 LTS, 14.0.2 that fix the problem described.
Credits Thanks to Georg Dümmler for reporting this issue, and to TYPO3 security team member Elias Häußler for fixing it.
References TYPO3-CORE-SA-2026-002
Other sources
Backend users with access to the redirects module and write permission on the sysredirect table were able to read, create, and modify any redirect record without restriction to the user’s own file-mounts or web-mounts. This allowed attackers to insert or alter redirects pointing to arbitrary URLs – facilitating phishing or other malicious redirect attacks. This issue affects TYPO3 CMS versions 10.0.0-10.4.54, 11.0.0-11.5.48, 12.0.0-12.4.40, 13.0.0-13.4.22 and 14.0.0-14.0.1.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59021?
CVE-2025-59021 is classified as a medium severity vulnerability due to the broken access control that allows unauthorized access to redirect records.
How do I fix CVE-2025-59021?
To fix CVE-2025-59021, update your TYPO3 CMS to a version above 14.0.1, 13.4.22, 12.4.40, 11.5.48, or 10.4.54.
What versions of TYPO3 CMS are affected by CVE-2025-59021?
CVE-2025-59021 affects TYPO3 CMS versions from 10.0.0 up to 10.4.54, 11.0.0 up to 11.5.48, 12.0.0 up to 12.4.40, 13.0.0 up to 13.4.22, and 14.0.0 up to 14.0.1.
What type of vulnerability is CVE-2025-59021?
CVE-2025-59021 is a broken access control vulnerability specifically in the redirects module of TYPO3 CMS.
Who is at risk due to CVE-2025-59021?
Backend users with access to the redirects module and write permission on the sys_redirect table are at risk due to CVE-2025-59021.