TYPO3 CMS - Open Redirect in Core Utilities
Summary
| CVE | CVE-2026-47347 |
|---|---|
| State | PUBLISHED |
| Assigner | TYPO3 |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-09 11:16:52 UTC |
| Updated | 2026-06-09 13:46:50 UTC |
| Description | Applications that use GeneralUtility::sanitizeLocalUrl to allow only local URLs are vulnerable to open redirect attacks if the URL is used after it has passed the aforementioned sanitization checks. This enables attackers to redirect users to external content and carry out phishing attacks. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2. |
Risk And Classification
Primary CVSS: v4.0 5.3 MEDIUM from f4fb688c-4412-4426-b4b8-421ecf27b14a
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.004840000 probability, percentile 0.377440000 (date 2026-06-16)
Problem Types: CWE-601 | CWE-601 CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | f4fb688c-4412-4426-b4b8-421ecf27b14a | Secondary | 5.3 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 5.3 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
NonePrivileges Required
NoneUser Interaction
PassiveConfidentiality
NoneIntegrity
NoneAvailability
NoneSub Conf.
NoneSub Integrity
LowSub Availability
NoneCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | TYPO3 | TYPO3 CMS | affected 10.4.57 semver | Not specified |
| CNA | TYPO3 | TYPO3 CMS | affected 11.0.0 11.5.51 semver | Not specified |
| CNA | TYPO3 | TYPO3 CMS | affected 12.0.0 12.4.46 semver | Not specified |
| CNA | TYPO3 | TYPO3 CMS | affected 13.0.0 13.4.31 semver | Not specified |
| CNA | TYPO3 | TYPO3 CMS | affected 14.0.0 14.3.3 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| typo3.org/security/advisory/typo3-core-sa-2026-009 | f4fb688c-4412-4426-b4b8-421ecf27b14a | typo3.org | |
| github.com/TYPO3/typo3/commit/3ffc0835012c6199db0e1dc4b56a77147d8600e0 | f4fb688c-4412-4426-b4b8-421ecf27b14a | github.com | |
| github.com/TYPO3/typo3/commit/22c2dd5398ebc4cb7aa4aa37e02cb39181dee0cd | f4fb688c-4412-4426-b4b8-421ecf27b14a | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Alexandre Romao (en)
CNA: Benjamin Franzke (en)
There are currently no legacy QID mappings associated with this CVE.