CVE-2026-77131
When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in cleartext instead of encrypting it. Exploitation requires the attacker to already be in control of the SYSSY project's API key.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.15%
- CWE
- CWE-319
- Published
- 2026-08-25
- Last modified
- 2026-08-25
Affected products
- TYPO3 Extension "SYSSY - TYPO3 Monitoring & Security Checks"
Weakness type
Related vulnerabilities
- CVE-2026-88013 — rclone: http backend forwards custom/auth headers to a different host on redirect
- CVE-2026-81330 — Softish C6 Ear Camera and EarVision Android Application Cleartext transmission of sensitive information
- CVE-2026-87482 — Cleartext transmission of sensitive data in HttpsUpgrades in Google Chrome on on iOS prior to...
- CVE-2026-71216 — Apache SkyWalking: PagerDuty alarm hook transmits the integration routing key over cleartext HTTP
- CVE-2026-84381 — HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies
- CVE-2026-84366 — Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default
- CVE-2026-55860 — MariaDB Connector/R2DBC: Cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)
- CVE-2026-55857 — MariaDB Connector/J: Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials