CVE-2026-77131
Cleartext Transmission of Sensitive Information in extension "SYSSY - TYPO3 Monitoring & Security Checks" (syssy)
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in cleartext instead of encrypting it. Exploitation requires the attacker to already be in control of the SYSSY project's API key.
| CWE | CWE-319 |
| Vendor | typo3 |
| Product | extension "syssy - typo3 monitoring & security checks" |
| Published | Aug 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for typo3 extension "syssy - typo3 monitoring & security checks"
Be the first to know when new unknown vulnerabilities affecting typo3 extension "syssy - typo3 monitoring & security checks" are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
TYPO3 / Extension "SYSSY - TYPO3 Monitoring & Security Checks"
0 < 3.0.6
References
Credits
Ingrid Stürmer