Miggo Logo

CVE-2020-25025: Incorrect Authorization in TYPO3 extension

4.3

CVSS Score
3.1

Basic Information

EPSS Score
0.33274%
Published
7/26/2021
Updated
2/1/2023
KEV Status
No
Technology
TechnologyPHP

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
localizationteam/l10nmgrcomposer< 7.4.07.4.0
localizationteam/l10nmgrcomposer>= 8.0.0, < 8.7.08.7.0
localizationteam/l10nmgrcomposer>= 9.0.0, < 9.2.09.2.0

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

The vulnerability centers on missing access controls for translatable field exports. TYPO3 backend modules typically use Controller actions for export functionality, and service classes for rendering. The advisory specifically mentions export-related information disclosure, implicating the export action handler and XML renderer. While exact code changes aren't visible, these components would logically require the added authorization checks mentioned in the advisory. Confidence is medium due to inference from vulnerability patterns in TYPO3 extensions rather than direct patch analysis.

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

T** l**nm*r (*k* Lo**liz*tion M*n***r) *xt*nsion ***or* *.*.*, *.x ***or* *.*.*, *n* *.x ***or* *.*.* *or TYPO* *llows In*orm*tion *is*losur* (tr*nsl*t**l* *i*l*s).

Reasoning

T** vuln*r**ility **nt*rs on missin* ****ss *ontrols *or tr*nsl*t**l* *i*l* *xports. TYPO* ***k*n* mo*ul*s typi**lly us* *ontroll*r **tions *or *xport *un*tion*lity, *n* s*rvi** *l*ss*s *or r*n**rin*. T** **visory sp**i*i**lly m*ntions *xport-r*l*t**