CyberRota Analysis
AI-GeneratedThe vulnerability affects OpenSSL within TYPO3, where system information is transmitted in cleartext when OpenSSL is unavailable, potentially exposing sensitive data. An attacker must already possess control of the SYSSY project's API key to exploit this weakness. Organizations using TYPO3 with OpenSSL should prioritize remediation to safeguard against potential information leakage.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in cleartext instead of encrypting it. Exploitation requires the attacker to already be in control of the SYSSY project's API key.