Extension "Apache Solr for TYPO3 - Enterprise Search" vulnerability

The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user access filter, unlike the regular search path. A visitor who can obtain or guess a valid Solr document id can retrieve documents through this lookup without the same access restrictions enforced elsewhere.

Published 25 Aug 2026Updated 17 Sep 20261 sources
CVSS 6.3

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.