{"id":"GHSA-49qv-h8pm-73pf","summary":"TYPO3 Modules Extension has Improper Authentication vulnerability ","details":"Improper Authentication vulnerability in TYPO3 Extension \"Modules\" codingms/modules. This issue affects Extension \"Modules\": before 4.3.11, from 5.0.0 before 5.7.4, from 6.0.0 before 6.4.2, from 7.0.0 before 7.5.5.","aliases":["CVE-2025-12998"],"modified":"2025-11-14T21:12:49.493506Z","published":"2025-11-12T12:30:28Z","database_specific":{"github_reviewed_at":"2025-11-14T20:46:30Z","nvd_published_at":"2025-11-12T12:15:39Z","cwe_ids":["CWE-287"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-12998"},{"type":"PACKAGE","url":"https://gitlab.com/codingms/typo3-public/modules"},{"type":"WEB","url":"https://gitlab.com/codingms/typo3-public/modules/-/commit/7fe0f9fbf2ea81343e4e8ede5a34c450c58d8ce1"},{"type":"WEB","url":"https://typo3.org/security/advisory/typo3-ext-sa-2025-015"}],"affected":[{"package":{"name":"codingms/modules","ecosystem":"Packagist","purl":"pkg:composer/codingms/modules"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.3.11"}]}],"versions":["3.0.1","3.1.0","3.1.1","3.1.2","3.2.0","4.0.0","4.0.1","4.0.2","4.0.3","4.0.4","4.1.0","4.1.1","4.1.2","4.1.3","4.1.4","4.1.5","4.1.6","4.2.0","4.2.1","4.2.2","4.2.3","4.2.4","4.2.5","4.2.6","4.2.7","4.2.8","4.2.9","4.3.0","4.3.1","4.3.10","4.3.2","4.3.3","4.3.4","4.3.5","4.3.6","4.3.7","4.3.8","4.3.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/11/GHSA-49qv-h8pm-73pf/GHSA-49qv-h8pm-73pf.json"}},{"package":{"name":"codingms/modules","ecosystem":"Packagist","purl":"pkg:composer/codingms/modules"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0"},{"fixed":"5.7.4"}]}],"versions":["5.0.0","5.1.0","5.1.1","5.1.2","5.1.3","5.1.4","5.2.0","5.2.1","5.2.2","5.3.0","5.4.0","5.4.1","5.5.0","5.6.0","5.7.0","5.7.1","5.7.2","5.7.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/11/GHSA-49qv-h8pm-73pf/GHSA-49qv-h8pm-73pf.json"}},{"package":{"name":"codingms/modules","ecosystem":"Packagist","purl":"pkg:composer/codingms/modules"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.0.0"},{"fixed":"7.5.5"}]}],"versions":["7.0.0","7.0.1","7.0.2","7.1.0","7.1.1","7.1.2","7.2.0","7.2.1","7.3.0","7.3.1","7.3.2","7.3.3","7.4.0","7.4.1","7.4.2","7.4.3","7.4.4","7.4.5","7.4.6","7.5.0","7.5.2","7.5.3","7.5.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/11/GHSA-49qv-h8pm-73pf/GHSA-49qv-h8pm-73pf.json"}},{"package":{"name":"codingms/modules","ecosystem":"Packagist","purl":"pkg:composer/codingms/modules"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.0.0"},{"fixed":"6.4.2"}]}],"versions":["6.0.0","6.0.1","6.1.0","6.1.1","6.1.2","6.2.0","6.2.1","6.2.2","6.2.3","6.2.4","6.2.5","6.2.6","6.2.7","6.2.8","6.2.9","6.3.0","6.3.1","6.4.0","6.4.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/11/GHSA-49qv-h8pm-73pf/GHSA-49qv-h8pm-73pf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}