Impact
The Content Consent extension fails to verify whether a referenced request any element and display its content. This IDOR vulnerability can expose internal content elements that should be restricted.
Affected Systems
TYPO3 systems using the content_consent extension through version 2.0.1 are affected. The issue does not extend to later releases, so upgrading beyond 2.0.1 removes the flaw.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, while the EPSS score is less than 1% and the vulnerability is not listed in CISA KEV. Unauthenticated attackers can exploit the IDOR without additional credentials, making it a realistic threat for publicly reachable TYPO3 sites. The risk is solidly moderate, with potential confidentiality impact if sensitive content is exposed.
OpenCVE Enrichment
Github GHSA