PT-2026-106018 · Unknown · Tf Content
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
TF Content versions 2.9.0 through 2.9.4
Description
The extension exposes the site task
records.custom action without authentication, Access Control List (ACL), Cross-Site Request Forgery (CSRF) protection, task-trigger, content-binding, or cron-token enforcement. This allows an unauthenticated guest to provide the numeric ID of any published TF Content task and force the component to execute its configured executor immediately.Recommendations
Update TF Content to a version later than 2.9.4.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tf Content