Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2026-016 |
|
Tue, 25 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The extension fails to restrict a backend AJAX endpoint for inline editing to fields the current user is permitted to see or edit. An authenticated, low-privileged backend user can supply arbitrary table, field and record parameters, and trigger an error response that discloses the current database value of the requested field, leading to disclosure of sensitive information such as backend and frontend user password hashes. Exploitation requires a valid, authenticated TYPO3 backend user account with access to the extensions backend module. | |
| Title | Information Disclosure in extension "Modules" (modules) | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: TYPO3
Published:
Updated: 2026-08-25T14:09:12.595Z
Reserved: 2026-08-20T13:10:12.062Z
Link: CVE-2026-77127
Updated: 2026-08-25T14:08:56.071Z
Status : Received
Published: 2026-08-25T09:17:32.860
Modified: 2026-08-25T14:16:53.943
Link: CVE-2026-77127
No data.
OpenCVE Enrichment
Updated: 2026-08-25T10:30:05Z