{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/club-directory/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-77141"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Club Directory"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["TYPO3"],"content_html":"\u003cp\u003eA critical broken access control vulnerability (CVE-2026-77141) has been identified in the TYPO3 'Club Directory' extension, version 4.0. The vulnerability originates from a failure to perform ownership checks within the extension's frontend edit, update, and activate actions. Because the application resolves the target club record based on a user-supplied request argument without verifying authorization, an unauthenticated visitor who possesses a valid club record UID can modify existing data or force the publication of records pending approval. This flaw presents a significant risk to data integrity within the TYPO3 CMS environment. Security teams should prioritize patching the extension as directed by the TYPO3 advisory.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify TYPO3 instances using the 'Club Directory' extension.\u003c/li\u003e\n\u003cli\u003eAttacker discovers or enumerates valid club record UIDs through public-facing directories or information disclosure.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP request targeting the extension's frontend update or activate controller actions.\u003c/li\u003e\n\u003cli\u003eAttacker inserts the identified record UID into the appropriate request argument parameter.\u003c/li\u003e\n\u003cli\u003eAttacker transmits the crafted request to the web server, bypassing authentication requirements.\u003c/li\u003e\n\u003cli\u003eThe application processes the request, failing to validate ownership of the provided UID.\u003c/li\u003e\n\u003cli\u003eThe application performs unauthorized modifications or publishes the target record.\u003c/li\u003e\n\u003cli\u003eData integrity is compromised, potentially leading to the injection of unauthorized content or destruction of existing records.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthenticated users to modify or publish records, which can lead to unauthorized information disclosure, unauthorized content injection, and disruption of site integrity. Given the 8.8 CVSS score, successful exploitation could lead to widespread unauthorized data manipulation across impacted TYPO3 installations that rely on the Club Directory extension for user-managed content.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate application of the security patches provided by the TYPO3 project in advisory TYPO3-EXT-SA-2026-019. Detection engineering teams should monitor web access logs for anomalous, high-frequency requests directed toward the Club Directory extension controller actions that include potential record UID parameters.\u003c/p\u003e\n","date_modified":"2026-08-25T16:17:32Z","date_published":"2026-08-25T16:17:32Z","id":"https://feed.craftedsignal.io/briefs/2026-08-typo3-club-directory-vulnerability/","summary":"An unauthenticated broken access control vulnerability in the TYPO3 Club Directory extension allows remote attackers to overwrite or publish club records by supplying a known record UID to frontend actions.","title":"Unauthenticated Access Control Vulnerability in TYPO3 Club Directory","url":"https://feed.craftedsignal.io/briefs/2026-08-typo3-club-directory-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Club Directory","version":"https://jsonfeed.org/version/1.1"}