Description
The sf_event_mgt (aka Event management and registration) extension before 4.3.1 and 5.x before 5.1.1 for TYPO3 allows Information Disclosure (participant data, and event data via email) because of Broken Access Control.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-1055 | The sf_event_mgt (aka Event management and registration) extension before 4.3.1 and 5.x before 5.1.1 for TYPO3 allows Information Disclosure (participant data, and event data via email) because of Broken Access Control. |
Github GHSA |
GHSA-g8rg-7rpr-cwr2 | Information Disclosure in TYPO3 extension sf_event_mgt |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T15:26:09.014Z
Reserved: 2020-08-30T00:00:00.000Z
Link: CVE-2020-25026
No data.
Status : Modified
Published: 2020-09-02T17:15:12.533
Modified: 2024-11-21T05:16:40.960
Link: CVE-2020-25026
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA