The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and field names. A backend user with permission to edit indexer configurations can copy sensitive data from internal TYPO3 tables into the search index.
CVSS
No CVSS.
References
Configurations
No configuration.
History
19 May 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-19 10:16
Updated : 2026-05-19 14:47
NVD link : CVE-2026-46723
Mitre link : CVE-2026-46723
CVE.ORG link : CVE-2026-46723
JSON object : View
Products Affected
No product.
CWE
CWE-668
Exposure of Resource to Wrong Sphere
