Data Exposure Vulnerability in TYPO3 from TYPO3 Association
CVE-2026-77131

5.3MEDIUM

What is CVE-2026-77131?

When the OpenSSL library is not available on the server, the TYPO3 extension transmits sensitive system information in cleartext rather than securely encrypting it. This vulnerability can be exploited if an attacker has control over the SYSSY project's API key, potentially leading to unauthorized information disclosure.

Affected Version(s)

Extension "SYSSY - TYPO3 Monitoring & Security Checks" 0 < 3.0.6

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ingrid StĂĽrmer
.