CVE-2024-24751

sf_event_mgt is an event management and registration extension for the TYPO3 CMS based on ExtBase and Fluid. In affected versions the existing access control check for events in the backend module got broken during the update of the extension to TYPO3 12.4, because the `RedirectResponse` from the `$this->redirect()` function was never handled. This issue has been addressed in version 7.4.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:derhansen:event_management_and_registration:7.0.0:*:*:*:*:typo3:*:*

History

18 Oct 2024, 18:13

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
First Time Derhansen event Management And Registration
Derhansen
References () https://github.com/derhansen/sf_event_mgt/commit/a08c2cd48695c07e462d15eeb70434ddc0206e4c - () https://github.com/derhansen/sf_event_mgt/commit/a08c2cd48695c07e462d15eeb70434ddc0206e4c - Patch
References () https://github.com/derhansen/sf_event_mgt/security/advisories/GHSA-4576-pgh2-g34j - () https://github.com/derhansen/sf_event_mgt/security/advisories/GHSA-4576-pgh2-g34j - Vendor Advisory
CWE CWE-284
CPE cpe:2.3:a:derhansen:event_management_and_registration:7.0.0:*:*:*:*:typo3:*:*

13 Feb 2024, 19:45

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-13 19:15

Updated : 2024-10-18 18:13


NVD link : CVE-2024-24751

Mitre link : CVE-2024-24751


JSON object : View

Products Affected

derhansen

  • event_management_and_registration
CWE
CWE-863

Incorrect Authorization