Improper access control in TYPO3 - CVE-2016-5091
Published: July 28, 2020 / Updated: November 18, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in Extbase request handling. A remote attacker can send a specially crafted request, bypass implemented security restrictions and execute arbitrary Extbase actions.
Affected software
Media Content Element
How to mitigate CVE-2016-5091
Media Content Element - update to 7.6.5