Lucene search

K
osvGoogleOSV:GHSA-G8RG-7RPR-CWR2
HistorySep 02, 2020 - 6:03 p.m.

Information Disclosure in TYPO3 extension sf_event_mgt

2020-09-0218:03:26
Google
osv.dev
11

0.001 Low

EPSS

Percentile

22.7%

A missing access check in the backend module allows an authenticated backend user to export participant data for events which the user does not have access to, resulting in Information Disclosure.

Another missing access check in the backend module allows an authenticated backend user to send emails to event participants for events which the user does not have access to, resulting in Broken Access Control.

External reference: https://typo3.org/security/advisory/typo3-ext-sa-2020-017

0.001 Low

EPSS

Percentile

22.7%

Related for OSV:GHSA-G8RG-7RPR-CWR2