The typo3_forum extension before 1.2.1 for TYPO3 has Incorrect Access Control.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15513
Reference (s):
- https://typo3.org/security/advisory/typo3-ext-sa-2020-010
- https://typo3.org/help/security-advisories

