TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to versions 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, administrator-level backend users without system maintainer privileges can escalate their privileges and gain system maintainer access. Exploiting this vulnerability requires a valid administrator account. Users should update to TYPO3 version 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, or 13.4.12 LTS to fix the problem.
{
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/47xxx/CVE-2025-47940.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "10.0.0"
},
{
"fixed": "10.4.50"
},
{
"introduced": "11.0.0"
},
{
"fixed": "11.5.44"
}
],
"source": "AFFECTED_FIELD"
}
],
"cwe_ids": [
"CWE-283"
]
}