PT-2025-22370 · Typo3 · Ns Backup

CVE-2025-48201

·

Publicado

2025-05-20

·

Atualizado

2025-12-27

CVSS v3.1

8.6

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ns backup extension for TYPO3 version 13.0.0 and earlier
Description The issue concerns a Predictable Resource Location in the ns backup extension for TYPO3. This allows an unauthenticated remote user to download created backups and configuration files.
Recommendations For versions 13.0.0 and earlier, consider disabling the ns backup extension until a patch is available to prevent unauthenticated access to backups and configuration files.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-05994
CVE-2025-48201
GHSA-HQ4F-5QJV-FWRG

Produtos afetados

Ns Backup