Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4239 articles · 196964 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-77141PATCHED
typo3 · extension "club directory"

Broken Access Control in extension "Club Directory" (clubdirectory)

Description

The extension resolves the targeted club record from a user-supplied request argument in its frontend edit, update, and activate actions, but performs no ownership check in any of them. An unauthenticated visitor who knows the UID of a club record can send a direct request to the update or activate action and overwrite that record, or publish one still awaiting approval, without owning it.

Affected Products

VendorProductVersions
typo3extension "club directory"0

References

  • https://typo3.org/security/advisory/typo3-ext-sa-2026-019(vendor-advisory)

Related News (1 articles)

Tier C
VulDB7h ago
CVE-2026-77141 | TYPO3 Club Directory Extension up to 8.1.2 privileges management
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
Patch available
8.1.3
CWECWE-862, CWE-639
PublishedAug 25, 2026
Trending Score29
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-77136EXPKEV
Server-Side Template Injection in extension "powermail" (powermail)
Trending: 92
NONECVE-2026-77138
Remote Code Execution in extension "HTML5 Video Player vs. Powermail" (html5videoplayer_powermail)
Trending: 34
NONECVE-2026-77143
Broken Access Control in extension "Forum" (pforum)
Trending: 29
NONECVE-2026-77142
Broken Access Control in extension "Industry Directory" (yellowpages2)
Trending: 29
NONECVE-2026-77140
Broken Access Control in extension "Telephone Directory" (telephonedirectory)
Trending: 29

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 25, 2026
Discovered by ZDM
Aug 25, 2026
Patch Available
Aug 25, 2026