Broken Access Control in extension "Industry Directory" (yellowpages2)
Published Aug 25, 2026
8.8
HIGHCVSS 4.0
EPSS 0.41%
Description
The frontend company self-service editing feature relies on a template-level visibility flag to hide the edit form for company records a visitor does not own, but the corresponding write operation does not repeat this ownership check on the server side. As a result, a visitor who knows the identifier of a company record from the public directory can submit a modified update request for that record directly and overwrite its data, without the application ever confirming that the visitor owns it.
Affected products
-
Affected
- ≥ 0, < 8.1.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| TYPO3 | Extension "Industry Directory" | unaffected | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-65334 Advisory
- https://typo3.org/security/advisory/typo3-ext-sa-2026-020 vendor-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-65334 | Advisory | |
| https://typo3.org/security/advisory/typo3-ext-sa-2026-020 | vendor-advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data