events2 TYPO3 extension insecure direct object reference (IDOR) vulnerability
Moderate severity
GitHub Reviewed
Published
Jun 21, 2024
to the GitHub Advisory Database
•
Updated Aug 2, 2024
Package
Affected versions
< 8.3.8
>= 9.0.0, < 9.0.6
Patched versions
8.3.8
9.0.6
Description
Published by the National Vulnerability Database
Jun 21, 2024
Published to the GitHub Advisory Database
Jun 21, 2024
Reviewed
Jun 21, 2024
Last updated
Aug 2, 2024
An issue was discovered in the events2 (aka Events 2) extension before 8.3.8 and 9.x before 9.0.6 for TYPO3. Missing access checks in the management plugin lead to an insecure direct object reference (IDOR) vulnerability with the potential to activate or delete various events for unauthenticated users.
References