Home

Description

The extension fails to verify, if an authenticated user has permissions to access to redirects resulting in exposure of redirect records when editing a page.

PUBLISHED Reserved 2026-03-15 | Published 2026-03-17 | Updated 2026-03-17 | Assigner TYPO3




LOW: 2.3CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-862

CWE-200

Product status

Default status
unaffected

4.0.0 (semver) before 4.0.5
affected

3.0.0 (semver) before 3.1.7
affected

Any version before 2.1.2
affected

Credits

Guido Schmechel reporter

Guido Schmechel remediation developer

References

typo3.org/security/advisory/typo3-ext-sa-2026-006 vendor-advisory

cve.org (CVE-2026-4202)

nvd.nist.gov (CVE-2026-4202)

Download JSON