Back

HIGH

Broken Access Control in extension "Industry Directory" (yellowpages2)

Published Aug 25, 2026

Description

The frontend company self-service editing feature relies on a template-level visibility flag to hide the edit form for company records a visitor does not own, but the corresponding write operation does not repeat this ownership check on the server side. As a result, a visitor who knows the identifier of a company record from the public directory can submit a modified update request for that record directly and overwrite its data, without the application ever confirming that the visitor owns it.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner TYPO3
Published Aug 25, 2026
Updated Aug 27, 2026
Reserved Aug 20, 2026

CISA Vulnrichment

Updated Aug 25, 2026

NVD

Status Deferred
Modified Aug 27, 2026

Red Hat

No data

ENISA EUVD

Assigner TYPO3
Published Aug 25, 2026
Updated Aug 27, 2026

GitHub

No data