Unauthorized Record Manipulation in TYPO3 Extension by TYPO3
CVE-2026-77141
8.8HIGH
What is CVE-2026-77141?
The TYPO3 extension allows unauthenticated users to manipulate club records without proper ownership checks during edit, update, and activate actions. This flaw enables a malicious visitor with knowledge of a record's UID to overwrite existing records or publish unapproved records, posing significant risks to website security and data integrity.
Affected Version(s)
Extension "Club Directory" 0 < 8.1.3
