PT-2024-28250 · Typo3 · Events2 Extension

Stefan Frömken

+1

·

Published

2024-06-21

·

Updated

2024-06-21

·

CVE-2024-38874

CVSS v3.1

5.4

Medium

VectorAC:L/AV:N/A:N/C:L/I:L/PR:L/S:U/UI:N
Name of the Vulnerable Software and Affected Versions events2 extension versions prior to 8.3.8 events2 extension versions 9.x prior to 9.0.6
Description An issue in the events2 extension for TYPO3 involves missing access checks in the management plugin, leading to an insecure direct object reference (IDOR) vulnerability. This vulnerability allows unauthenticated users to potentially activate or delete various events.
Recommendations For events2 extension version prior to 8.3.8, update to version 8.3.8 or later. For events2 extension version 9.x prior to 9.0.6, update to version 9.0.6 or later.

Exploit

Fix

Protection Mechanism Failure

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-38874
GHSA-CCHP-3RQ6-69WJ

Affected Products

Events2 Extension