CVE-2025-59015

Severity CVSS v4.0:
MEDIUM
Type:
CWE-331 Insufficient Entropy
Publication date:
09/09/2025
Last modified:
10/09/2025

Description

A deterministic three‑character prefix in the Password Generation component of TYPO3 CMS versions 12.0.0–12.4.36 and 13.0.0–13.4.17 reduces entropy, allowing attackers to carry out brute‑force attacks more quickly.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* 12.0.0 (including) 12.4.37 (excluding)
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* 13.0.0 (including) 13.4.18 (excluding)


References to Advisories, Solutions, and Tools