PT-2025-22138 · Typo3 · Typo3
Published
2025-05-20
·
Updated
2025-09-03
·
CVE-2025-47936
CVSS v3.1
4.4
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
TYPO3 versions 12.x prior to 12.4.31 LTS
TYPO3 versions 13.x prior to 13.4.2 LTS
Description:
The issue concerns Cross-Site Request Forgery (CSRF) in Webhooks, which can be exploited by adversaries to target internal resources, such as localhost or other services on the local network. This exploit requires an administrator-level backend user account. It enables attackers to access systems that would otherwise be inaccessible.
Recommendations:
For TYPO3 versions 12.x prior to 12.4.31 LTS, update to version 12.4.31 LTS to fix the problem.
For TYPO3 versions 13.x prior to 13.4.2 LTS, update to version 13.4.12 LTS to fix the problem.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Typo3