Improper Input Validation in TYPO3 Extension Affects User Record Editing
CVE-2026-77140
8.7HIGH
What is CVE-2026-77140?
The TYPO3 extension contains a flaw where the HMAC validation for editing employee records is only performed when rendering the edit form. This oversight leaves a significant security gap, allowing unauthenticated users who are aware of a valid employee UID to directly issue a POST request to the update action. Consequently, they can overwrite employee records without requiring a legitimate edit link or any ownership verification, posing a threat to sensitive data integrity.
Affected Version(s)
Extension "Telephone Directory" 0 < 6.2.0
