Impact
The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthenticated remote user can pass a demand-override parameter to view hidden or time‑restricted events, unless the disableOverrideDemand plugin setting is active. The flaw, categorized as CWE‑862, allows bypassing intended access controls and exposing event data that should remain confidential or time‑locked.
Affected Systems
The affected product is the Event management and registration extension (sf_event_mgt) for TYPO3. No specific version information is disclosed in the advisory, but any installation of this extension that has not applied the vendor’s recent fix is vulnerable.
Risk and Exploitability
The CVSS score of 6.3 indicates medium severity. EPSS is not available, so quantitative exploitation probability cannot be determined. Because the attack requires only a crafted HTTP request with the override parameter and does not need authentication, the attacker can remotely gain access to unprotected event records. As the issue is not listed in the CISA KEV catalog, it has not yet been observed in widespread exploitation, but the potential impact warrants cautious mitigation.
OpenCVE Enrichment