4.3
CVE-2026-4202
- EPSS 0.16%
- Veröffentlicht 17.03.2026 08:33:40
- Zuletzt bearbeitet 25.04.2026 18:40:02
- Quelle f4fb688c-4412-4426-b4b8-421ecf
- CVE-Watchlists
- Unerledigt
Broken Access Control in extension "Redirect Tab"
The extension fails to verify, if an authenticated user has permissions to access to redirects resulting in exposure of redirect records when editing a page.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ayacoo ≫ Redirect Tab SwPlatformtypo3 Version < 2.1.2
Ayacoo ≫ Redirect Tab SwPlatformtypo3 Version >= 3.0.0 < 3.1.7
Ayacoo ≫ Redirect Tab SwPlatformtypo3 Version >= 4.0.0 < 4.0.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.057 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| f4fb688c-4412-4426-b4b8-421ecf27b14a | 2.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
https://typo3.org/security/advisory/typo3-ext-sa-2026-006