Executive brief
The sf_register extension for TYPO3, which manages website user registration and profile editing, contains a security flaw that allows users to assign themselves to any user group. By submitting unauthorized data during registration or profile updates, an attacker can gain access to restricted content or administrative features intended only for specific member groups. This could lead to unauthorized access to sensitive information or restricted site functionality.
Technical details
A vulnerability exists in the 'create' and 'edit' flows of the TYPO3 sf_register extension due to insufficient input validation and lack of access control on frontend user group assignments (CWE-639). The extension does not restrict which user properties can be submitted via frontend forms. A remote, unauthenticated attacker can exploit this by injecting specific user group identifiers into the registration or profile update request. Successful exploitation allows the attacker to elevate their privileges by joining restricted frontend user groups, potentially gaining access to protected content. The issue is resolved in versions 13.2.4 and 14.0.2.
Affected products
- evoweb sf_register >= 14.0.0, < 14.0.2
- evoweb sf_register < 13.2.4
Timeline
- 2026-05-19: advisory
- 2026-05-19: disclosed
References
- https://api.github.com/users/eliashaeussler
- https://github.com/eliashaeussler
- https://api.github.com/users/eliashaeussler/gists%7B/gist_id%7D
- https://api.github.com/users/eliashaeussler/repos
- https://avatars.githubusercontent.com/u/16313625?v=4
- https://api.github.com/users/eliashaeussler/events%7B/privacy%7D