IDOR Vulnerability in Content Consent Extension for TYPO3
CVE-2023-50462

5.3MEDIUM

Key Information:

Vendor

Typo3

Vendor
CVE Published:
14 September 2026

What is CVE-2023-50462?

A vulnerability was identified in the Content Consent extension for TYPO3, where the plugin does not properly verify the permissions for specified content element identifiers. This oversight allows unauthenticated users to access and potentially display various internal content elements, which could lead to unauthorized information exposure. Website administrators should take immediate action to update the extension and ensure that security measures are in place to mitigate the risk of unauthorized access.

Affected Version(s)

content_consent 0 < 1.0.3

content_consent 2.0.0 < 2.0.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.