CVE Details
Basic Information
| Title |
CVE-2025-47938 |
| Type |
cve |
| Published |
2025-05-20T14:15:50 |
| Last Seen |
2025-05-20T14:26:26 |
CVSS Information
| Base Score |
3.8 (LOW) |
| Attack Vector |
NETWORK |
| Attack Complexity |
LOW |
| Privileges Required |
HIGH |
| User Interaction |
NONE |
| Scope |
UNCHANGED |
| Confidentiality Impact |
LOW |
| Integrity Impact |
LOW |
| Availability Impact |
NONE |
AI Analysis
| AI Description |
A vulnerability in TYPO3 CMS allows authenticated backend users to manipulate certain settings, potentially leading to unauthorized changes. The issue arises from improper validation of user input in the backend user management interface. |
| AI Severity |
Medium |
| Vendor |
TYPO3 |
| Product |
TYPO3 CMS |
| Affected Version |
9.0.0 to 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS |
Additional Information
| CVE List |
CVE-2025-47938 |
| CWE List |
CWE-620 |
| Bulletin Family |
cve |
Description
TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, the backend user management…
CVSS Score Summary
Base Score: %!f(string=#) (LOW)
View Full CVE Details