CVE-2026-77140
Broken Access Control in extension "Telephone Directory" (telephonedirectory)
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The extension validates the HMAC of a frontend employee edit link only in the action that renders the edit form, not in the action that persists the change. An unauthenticated visitor who knows the UID of a visible employee record can send a direct POST request to the update action and overwrite that record without a valid edit link or any ownership check.
| CWE | CWE-862 CWE-639 |
| Vendor | typo3 |
| Product | extension "telephone directory" |
| Published | Aug 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for typo3 extension "telephone directory"
Be the first to know when new unknown vulnerabilities affecting typo3 extension "telephone directory" are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
TYPO3 / Extension "Telephone Directory"
0 < 6.2.0
References
Credits
๐ Seungbin Yang Hoja Mustaffa Abdul Latheef