Description
alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, an attacker can access data from other organizers. The attacker can use a specially crafted request to receive the e-mail log sent by other events. Version 2.0-M4-2402 fixes this issue.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-22952 | alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, an attacker can access data from other organizers. The attacker can use a specially crafted request to receive the e-mail log sent by other events. Version 2.0-M4-2402 fixes this issue. |
References
History
Wed, 18 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Alf
Alf alf |
|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:alf:alf:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Alf
Alf alf |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-01T23:44:09.810Z
Reserved: 2024-02-08T22:26:33.513Z
Link: CVE-2024-25634
Updated: 2024-08-01T23:44:09.810Z
Status : Analyzed
Published: 2024-02-19T20:15:45.707
Modified: 2024-12-18T17:55:31.463
Link: CVE-2024-25634
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD