CVE-2025-48201 Details
Description
The ns_backup extension through 13.0.0 for TYPO3 has a Predictable Resource Location.
A predictable resource location vulnerability has been identified in the Backup Plus extension (ns_backup) for TYPO3, affecting versions through 13.0.0. This vulnerability allows an unauthenticated remote user to download backup and configuration files, as the extension saves these files to a location that can be easily guessed.
Users are advised to update the Backup Plus extension to version 13.0.1, available through the TYPO3 extension manager, Packagist, or the TYPO3 Extensions Repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 21, 2025CISA-ADP
Assessed May 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2025-007 | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-425 | Direct Request ('Forced Browsing') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| TYPO3 ns_backup | <= 13.0.0 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 21, 2025 | New CVE Received | [email protected] |
Volerion