CVE-2021-43563 is a critical access control vulnerability affecting the pixxio (aka pixx.io integration or DAM) extension for TYPO3, specifically versions prior to 1.0.6. This flaw allows an unauthenticated attacker to bypass access controls in the media browser, enabling them to make requests to the pixx.io API using the configured API user's credentials. This results in the unauthorized download of various media files from the Digital Asset Management (DAM) system. The vulnerability carries a high CVSS score of 8.8, indicating a severe risk. Its attack vector is network-based with low attack complexity, requiring no user interaction or elevated privileges, and can lead to high confidentiality, integrity, and availability impacts. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has also garnered minimal community discussion and media coverage, suggesting a low level of public awareness or attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.6CPE matchmatch criteria | cpe:2.3:a:pixxio:pixx.io:*:*:*:*:*:typo3:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.