๐Ÿ” CVE Alert

CVE-2026-77142

UNKNOWN 0.0

Broken Access Control in extension "Industry Directory" (yellowpages2)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The frontend company self-service editing feature relies on a template-level visibility flag to hide the edit form for company records a visitor does not own, but the corresponding write operation does not repeat this ownership check on the server side. As a result, a visitor who knows the identifier of a company record from the public directory can submit a modified update request for that record directly and overwrite its data, without the application ever confirming that the visitor owns it.

CWE CWE-862 CWE-639
Vendor typo3
Product extension "industry directory"
Published Aug 25, 2026
Stay Ahead of the Next One

Get instant alerts for typo3 extension "industry directory"

Be the first to know when new unknown vulnerabilities affecting typo3 extension "industry directory" are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

TYPO3 / Extension "Industry Directory"
0 < 8.1.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
typo3.org: https://typo3.org/security/advisory/typo3-ext-sa-2026-020

Credits

๐Ÿ” Seungbin Yang Hoja Mustaffa Abdul Latheef