EIP-2026-112836

PRE-CVE

Typo3 3.5 b5 - HTML Hidden Form Field Information Disclosure (2)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-112836. PoCs published by Martin Eiszner.

AI-analyzed exploit summary This Perl script exploits an authentication bypass vulnerability in TYPO3 by leveraging hidden form fields and MD5-based challenge-response authentication. It automates login by crafting a valid 'userident' token from the username, password, and challenge value.

Description

Typo3 3.5 b5 - HTML Hidden Form Field Information Disclosure (2)

Exploits (1)

exploitdb WORKING POC VERIFIED
by Martin Eiszner · perlwebappsphp
https://www.exploit-db.com/exploits/22316

This Perl script exploits an authentication bypass vulnerability in TYPO3 by leveraging hidden form fields and MD5-based challenge-response authentication. It automates login by crafting a valid 'userident' token from the username, password, and challenge value.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: TYPO3 (version not specified)
No auth needed
Prerequisites: Valid username and password for the target TYPO3 instance · Access to the TYPO3 login page
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026