
Cloud Vulnerability DB
A community-led vulnerabilities database
The l10nmgr (Localization Manager) extension before versions 7.4.0, 8.7.0, and 9.2.0 for TYPO3 contains an information disclosure vulnerability that affects translatable fields. The vulnerability was discovered in September 2020 and assigned CVE-2020-25025 (Vendor Advisory).
The vulnerability stems from a missing access check in the extension that allows authenticated backend users to view and export data of translatable fields outside of their authorized access scope. The vulnerability has been assigned a CVSS v3.1 base score of 4.3 MEDIUM with the vector string: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N (NVD).
When exploited, this vulnerability allows authenticated backend users to access and export translation data that should be restricted based on their access permissions, leading to unauthorized information disclosure (Vendor Advisory).
The vulnerability requires an authenticated backend user account to exploit, but has low complexity and requires no user interaction to execute. The attack can be performed remotely (NVD).
The vulnerability has been fixed in versions 7.4.0, 8.7.0, and 9.2.0 of the extension. Users are advised to update to these patched versions as soon as possible. The updated versions can be obtained through the TYPO3 extension manager, Packagist, or downloaded directly from the TYPO3 extension repository (Vendor Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."