CVE-2025-9573: Command Injection in extension "TYPO3 Backup Plus" (ns_backup)
Published Sep 2, 2025
·Updated
The nsbackup extension through 13.0.2 for TYPO3 allows command injection.
Affected Software
1 affected component
Typo3 Backup Plus<13.0.2
Event History
Sep 2, 2025
CVE Published
via MITRE·08:42 AM
Data Sourced
via MITRE·08:42 AM
DescriptionWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Feb 28, 57989
Event
via FIRST·06:59 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-9573?
CVE-2025-9573 is classified as a critical vulnerability due to its potential for command injection.
2
How do I fix CVE-2025-9573?
To mitigate CVE-2025-9573, upgrade the TYPO3 ns_backup extension to version 13.0.3 or higher.
3
What software is affected by CVE-2025-9573?
CVE-2025-9573 affects the ns_backup extension of TYPO3 versions up to and including 13.0.2.
4
What type of vulnerability is CVE-2025-9573?
CVE-2025-9573 is a command injection vulnerability.
5
How can CVE-2025-9573 be exploited?
CVE-2025-9573 can be exploited by an attacker sending specially crafted input to the affected TYPO3 extension.