CVE-2011-4904: TYPO3

Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.

TYPO3 before 4.4.9 and 4.5.x before 4.5.4 does not apply proper access control on ExtDirect calls which allows remote attackers to retrieve ExtDirect endpoint services.

Affected products

  • TYPO3 TYPO3: from 4.4.0, before 4.4.9 (fixed in 4.4.9); from 4.5.0, before 4.5.4 (fixed in 4.5.4)

Published 2019-11-06. Last modified 2026-06-16.