Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2026-020 |
|
Tue, 25 Aug 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The frontend company self-service editing feature relies on a template-level visibility flag to hide the edit form for company records a visitor does not own, but the corresponding write operation does not repeat this ownership check on the server side. As a result, a visitor who knows the identifier of a company record from the public directory can submit a modified update request for that record directly and overwrite its data, without the application ever confirming that the visitor owns it. | |
| Title | Broken Access Control in extension "Industry Directory" (yellowpages2) | |
| Weaknesses | CWE-639 CWE-862 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: TYPO3
Published:
Updated: 2026-08-25T09:00:35.035Z
Reserved: 2026-08-20T13:10:15.962Z
Link: CVE-2026-77142
No data.
Status : Received
Published: 2026-08-25T09:17:35.133
Modified: 2026-08-25T09:17:35.133
Link: CVE-2026-77142
No data.
OpenCVE Enrichment
Updated: 2026-08-25T11:15:04Z