Impact
A TYPO3 backend AJAX endpoint in the "Modules" extension does not enforce field‑level permissions. An authenticated user with low privileges can supply any table, field and record parameters and receive an error response containing the current database value of that field. This allows disclosure of sensitive data such as backend and frontend password hashes. The flaw is a classic information‑exposure weakness (CWE‑639).
Affected Systems
The vulnerability targets the TYPO3 extension "Modules" used within TYPO3 installations. No specific version range is listed; any installation that includes the current, unpatched extension may be affected.
Risk and Exploitability
The CVSS score of 6 indicates a medium degree of risk. Exploitation requires a valid backend account with access to the extension’s backend module, but the attacker can request arbitrary data once authenticated. The EPSS score is not available, so the current likelihood of real‑world exploitation is uncertain, and the vulnerability is not listed in the CISA KEV catalog. Overall, the threat level is moderate, and the risk primarily concerns data confidentiality for users who have permissions to access the extension module.
OpenCVE Enrichment