PT-2025-22370 · Typo3 · Ns Backup
CVE-2025-48201
·
Publicado
2025-05-20
·
Atualizado
2025-12-27
CVSS v3.1
8.6
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ns backup extension for TYPO3 version 13.0.0 and earlier
Description
The issue concerns a Predictable Resource Location in the ns backup extension for TYPO3. This allows an unauthenticated remote user to download created backups and configuration files.
Recommendations
For versions 13.0.0 and earlier, consider disabling the ns backup extension until a patch is available to prevent unauthenticated access to backups and configuration files.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ns Backup