typo3/cms-backend is vulnerable to Missing Authorization
53
Medium Risk
Several AJAX routes used by the backend localization wizard skip authorization checks before returning record and content-element metadata. An authenticated low-privileged backend user can therefore read information about records outside their permitted range. The fix enforces authorization on those localization wizard AJAX routes.
You are affected if you are using a version that falls within the vulnerable range and low-privileged backend users can access the localization wizard AJAX routes.
typo3/cms-backend is vulnerable to Missing Authorization in versions 10.0.0 - 13.4.34 and 14.0.0 - 14.3.6.
Upgrade the typo3/cms-backend library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.