-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| t3s/content-consent | composer | >= 2.0.0, < 2.0.2 | 2.0.2 |
| t3s/content-consent | composer | < 1.0.3 | 1.0.3 |
The vulnerability stems from missing authorization checks when processing content element display requests. In TYPO3 MVC architecture:
While no patch diffs are available, the advisory explicitly states the lack of permission verification for content element identifiers. This indicates:
These functions would appear in runtime profiles when processing malicious requests as they directly handle the vulnerable parameter flow. Confidence is medium due to inference from advisory text rather than explicit patch analysis.
Ongoing coverage of React2Shell