Impact
A broken access control flaw in the TYPO3 "Events 2" extension allows users with frontend event management access to modify events belonging to other organizers. The permission check erroneously verifies a different event than the one being updated, so legitimate users can alter data they should not have control over. This vulnerability grants a user the ability to change event details, schedules, or other sensitive information that belongs to a different organizer, potentially impacting data integrity and organizational trust. The likely attack vector is an authenticated session through the normal front‑end management web interface, and based on the description it is inferred that an attacker must possess frontend event management rights to exploit the flaw.
Affected Systems
The affected system is the TYPO3 CMS extension called "Events 2". No specific version information is provided, so any deployment of this extension needs to be reviewed for the presence of the described flaw.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity with potential for significant impact on data integrity. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, suggesting no widespread public exploitation has yet been documented. Likely exploitation would be performed through the normal front‑end management web interface by a legitimate user with event management permissions. Because the flaw relies on an internal permission verification error, it requires authenticated access but does not enable remote code execution or privilege escalation beyond the affected user’s role.
OpenCVE Enrichment