Executive brief
The Content Consent extension for TYPO3 fails to properly validate access to content elements, allowing unauthenticated users to view any content element by guessing or enumerating its identifier. This could expose internal or restricted content such as draft articles, private messages, or sensitive data that should only be visible to authorized users.
Technical details
The vulnerability is an Insecure Direct Object Reference (IDOR) in the Content Consent extension for TYPO3, affecting versions 1.0.2 and earlier, and 2.0.0 through 2.0.1. The extension fails to validate whether a user has permission to view a specific content element identifier before displaying it. An unauthenticated attacker can access the plugin's endpoints with arbitrary content element identifiers and retrieve content that should be restricted. No authentication or user interaction is required—the attacker simply needs network access to the TYPO3 instance. The issue permits complete disclosure of content elements protected by the extension, potentially exposing internal or sensitive information. Fixed versions 1.0.3 and 2.0.2 are available and should be applied immediately.
Affected products
- TYPO3 Content Consent extension 1.0.2 and below, 2.0.0 - 2.0.1
Timeline
- 2023-12-13: disclosed
- 2023-12-13: advisory