The sf_event_mgt (aka Event management and registration) extension before 4.3.1 and 5.x before 5.1.1 for TYPO3 allows Information Disclosure (participant data, and event data via email) because of Broken Access Control.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-1055 | The sf_event_mgt (aka Event management and registration) extension before 4.3.1 and 5.x before 5.1.1 for TYPO3 allows Information Disclosure (participant data, and event data via email) because of Broken Access Control. |
Github GHSA |
GHSA-g8rg-7rpr-cwr2 | Information Disclosure in TYPO3 extension sf_event_mgt |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T15:26:09.014Z
Reserved: 2020-08-30T00:00:00
Link: CVE-2020-25026
No data.
Status : Modified
Published: 2020-09-02T17:15:12.533
Modified: 2024-11-21T05:16:40.960
Link: CVE-2020-25026
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA