CVE-2024-24751

sf_event_mgt is an event management and registration extension for the TYPO3 CMS based on ExtBase and Fluid. In affected versions the existing access control check for events in the backend module got broken during the update of the extension to TYPO3 12.4, because the `RedirectResponse` from the `$this->redirect()` function was never handled. This issue has been addressed in version 7.4.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:derhansen:event_management_and_registration:7.0.0:*:*:*:*:typo3:*:*

History

21 Nov 2024, 08:59

Type Values Removed Values Added
References () https://github.com/derhansen/sf_event_mgt/commit/a08c2cd48695c07e462d15eeb70434ddc0206e4c - Patch () https://github.com/derhansen/sf_event_mgt/commit/a08c2cd48695c07e462d15eeb70434ddc0206e4c - Patch
References () https://github.com/derhansen/sf_event_mgt/security/advisories/GHSA-4576-pgh2-g34j - Vendor Advisory () https://github.com/derhansen/sf_event_mgt/security/advisories/GHSA-4576-pgh2-g34j - Vendor Advisory
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 4.3

18 Oct 2024, 18:13

Type Values Removed Values Added
CPE cpe:2.3:a:derhansen:event_management_and_registration:7.0.0:*:*:*:*:typo3:*:*
CVSS v2 : unknown
v3 : 4.3
v2 : unknown
v3 : 8.8
References () https://github.com/derhansen/sf_event_mgt/commit/a08c2cd48695c07e462d15eeb70434ddc0206e4c - () https://github.com/derhansen/sf_event_mgt/commit/a08c2cd48695c07e462d15eeb70434ddc0206e4c - Patch
References () https://github.com/derhansen/sf_event_mgt/security/advisories/GHSA-4576-pgh2-g34j - () https://github.com/derhansen/sf_event_mgt/security/advisories/GHSA-4576-pgh2-g34j - Vendor Advisory
First Time Derhansen event Management And Registration
Derhansen

13 Feb 2024, 19:45

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-13 19:15

Updated : 2024-11-21 08:59


NVD link : CVE-2024-24751

Mitre link : CVE-2024-24751

CVE.ORG link : CVE-2024-24751


JSON object : View

Products Affected

derhansen

  • event_management_and_registration
CWE
CWE-284

Improper Access Control

CWE-863

Incorrect Authorization