AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-43563

HIGH · CVSS 8.8 EPSS 0.96%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-11-10 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2021-43563
Severity
HIGH
CVSS
8.8
EPSS
0.96%

Original NVD Description

An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The Access Control in the bundled media browser is broken, which allows an unauthenticated attacker to perform requests to the pixx.io API for the configured API user. This allows an attacker to download various media files from the DAM system.