EIP-2026-112836
PRE-CVETypo3 3.5 b5 - HTML Hidden Form Field Information Disclosure (2)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112836. PoCs published by Martin Eiszner.
AI-analyzed exploit summary This Perl script exploits an authentication bypass vulnerability in TYPO3 by leveraging hidden form fields and MD5-based challenge-response authentication. It automates login by crafting a valid 'userident' token from the username, password, and challenge value.
Description
Typo3 3.5 b5 - HTML Hidden Form Field Information Disclosure (2)
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Martin Eiszner · perlwebappsphp
https://www.exploit-db.com/exploits/22316
This Perl script exploits an authentication bypass vulnerability in TYPO3 by leveraging hidden form fields and MD5-based challenge-response authentication. It automates login by crafting a valid 'userident' token from the username, password, and challenge value.
Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target:
TYPO3 (version not specified)
No auth needed
Prerequisites:
Valid username and password for the target TYPO3 instance · Access to the TYPO3 login page
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026