Description
The extension passes an editor-configurable email subject string directly into a Fluid template source without restriction. A backend user with edit access to the event plugin or Backend Module can supply Fluid ViewHelper syntax in this field to disclose sensitive data or execute TypoScript content objects. Exploitation of this issue requires an authenticated backend account with edit access to the event registration plugin or backend module.
Published: 2026-08-25
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The "Event management and registration" extension forwards an editor‑configurable email subject string directly into a Fluid template without any validation. A backend user with edit privileges can embed Fluid ViewHelper syntax in this field, allowing disclosure of sensitive data or execution of arbitrary TypoScript objects. The vulnerability requires an authenticated backend account that can edit the event plugin or module; it is not exploitable by anonymous users.

Affected Systems

TYPO3 installations that have the sf_event_mgt extension included are impacted. The advisory indicates that versions prior to the patched release contain this deficiency; no specific version range is listed, so any older revision of the extension may be vulnerable.

Risk and Exploitability

The CVSS score of 7.7 signals high severity. While EPSS data is not available, the lack of KEV listing suggests no publicly known exploitation yet. Recognition that an attacker must first obtain backend editing rights limits the risk to environments where such privileged accounts exist. If compromised, the attacker could read or modify confidential information and execute custom TypoScript, potentially impacting data integrity and confidentiality.

Generated by OpenCVE AI on August 25, 2026 at 10:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the sf_event_mgt extension to the patched version provided by the vendor.
  • If an upgrade is not immediately possible, disable or lock the editor‑configurable email subject field so that it cannot be modified by end users.
  • Apply least privilege principles by restricting backend edit access to trusted users only and monitor for anomalous changes to the event plugin configuration.

Generated by OpenCVE AI on August 25, 2026 at 10:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Description The extension passes an editor-configurable email subject string directly into a Fluid template source without restriction. A backend user with edit access to the event plugin or Backend Module can supply Fluid ViewHelper syntax in this field to disclose sensitive data or execute TypoScript content objects. Exploitation of this issue requires an authenticated backend account with edit access to the event registration plugin or backend module.
Title Server-Side Template Injection in extension "Event management and registration" (sf_event_mgt)
Weaknesses CWE-1336
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TYPO3

Published:

Updated: 2026-08-25T09:00:44.104Z

Reserved: 2026-08-20T13:10:12.062Z

Link: CVE-2026-77129

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T09:17:33.200

Modified: 2026-08-25T09:17:33.200

Link: CVE-2026-77129

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T10:30:05Z

Weaknesses
  • CWE-1336

    Improper Neutralization of Special Elements Used in a Template Engine