Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g8rg-7rpr-cwr2

Опубликовано: 02 сент. 2020
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Information Disclosure in TYPO3 extension sf_event_mgt

A missing access check in the backend module allows an authenticated backend user to export participant data for events which the user does not have access to, resulting in Information Disclosure.

Another missing access check in the backend module allows an authenticated backend user to send emails to event participants for events which the user does not have access to, resulting in Broken Access Control.

External reference: https://typo3.org/security/advisory/typo3-ext-sa-2020-017

Пакеты

Наименование

derhansen/sf_event_mgt

composer
Затронутые версииВерсия исправления

< 4.3.1

4.3.1

Наименование

derhansen/sf_event_mgt

composer
Затронутые версииВерсия исправления

>= 5.0.0, < 5.1.1

5.1.1

EPSS

Процентиль: 42%
0.00197
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.3
nvd
больше 5 лет назад

The sf_event_mgt (aka Event management and registration) extension before 4.3.1 and 5.x before 5.1.1 for TYPO3 allows Information Disclosure (participant data, and event data via email) because of Broken Access Control.

EPSS

Процентиль: 42%
0.00197
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863