Impact
The "Event management and registration" extension forwards an editor‑configurable email subject string directly into a Fluid template without any validation. A backend user with edit privileges can embed Fluid ViewHelper syntax in this field, allowing disclosure of sensitive data or execution of arbitrary TypoScript objects. The vulnerability requires an authenticated backend account that can edit the event plugin or module; it is not exploitable by anonymous users.
Affected Systems
TYPO3 installations that have the sf_event_mgt extension included are impacted. The advisory indicates that versions prior to the patched release contain this deficiency; no specific version range is listed, so any older revision of the extension may be vulnerable.
Risk and Exploitability
The CVSS score of 7.7 signals high severity. While EPSS data is not available, the lack of KEV listing suggests no publicly known exploitation yet. Recognition that an attacker must first obtain backend editing rights limits the risk to environments where such privileged accounts exist. If compromised, the attacker could read or modify confidential information and execute custom TypoScript, potentially impacting data integrity and confidentiality.
OpenCVE Enrichment