CVE-2026-4202

Severity CVSS v4.0:
LOW
Type:
CWE-200 Information Leak / Disclosure
Publication date:
17/03/2026
Last modified:
25/04/2026

Description

The extension fails to verify, if an authenticated user has permissions to access to redirects resulting in exposure of redirect records when editing a page.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ayacoo:redirect_tab:*:*:*:*:*:typo3:*:* 2.1.2 (excluding)
cpe:2.3:a:ayacoo:redirect_tab:*:*:*:*:*:typo3:*:* 3.0.0 (including) 3.1.7 (excluding)
cpe:2.3:a:ayacoo:redirect_tab:*:*:*:*:*:typo3:*:* 4.0.0 (including) 4.0.5 (excluding)


References to Advisories, Solutions, and Tools