Description
TYPO3 before 4.4.9 and 4.5.x before 4.5.4 does not apply proper access control on ExtDirect calls which allows remote attackers to retrieve ExtDirect endpoint services.
Remediation
References
Related Vulnerabilities
WordPress Plugin Simple Image Sizes Unspecified Vulnerability (2.2.4)
WordPress Plugin OAuth client Single Sign On for WordPress (OAuth 2.0 SSO) Security Bypass (3.0.3)
WebLogic CVE-2020-2519 Vulnerability (CVE-2020-2519)
WordPress Plugin Ultimate WP Query Search Filter Cross-Site Scripting (1.0.10)