PT-2024-28250 · Typo3 · Events2 Extension
Stefan Frömken
+1
·
Published
2024-06-21
·
Updated
2024-06-21
·
CVE-2024-38874
CVSS v3.1
5.4
Medium
| Vector | AC:L/AV:N/A:N/C:L/I:L/PR:L/S:U/UI:N |
Name of the Vulnerable Software and Affected Versions
events2 extension versions prior to 8.3.8
events2 extension versions 9.x prior to 9.0.6
Description
An issue in the events2 extension for TYPO3 involves missing access checks in the management plugin, leading to an insecure direct object reference (IDOR) vulnerability. This vulnerability allows unauthenticated users to potentially activate or delete various events.
Recommendations
For events2 extension version prior to 8.3.8, update to version 8.3.8 or later.
For events2 extension version 9.x prior to 9.0.6, update to version 9.0.6 or later.
Exploit
Fix
Protection Mechanism Failure
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Events2 Extension