CVE-2020-25026
Last modified
CVE-2020-25026 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The sf_event_mgt (aka Event management and registration) extension before 4.3.1 and 5.x before 5.1.1 for TYPO3 allows Information Disclosure (participant data, and event data via email) because of Broken Access Control.. EPSS estimates a 0.77% chance of exploitation in the next 30 days.
Description
The sf_event_mgt (aka Event management and registration) extension before 4.3.1 and 5.x before 5.1.1 for TYPO3 allows Information Disclosure (participant data, and event data via email) because of Broken Access Control.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Derhansen | Event Management And Registration | < 4.3.1 |
| Derhansen | Event Management And Registration | >= 5.0.0, < 5.1.1 |
References
- https://typo3.org/help/security-advisoriesVendor Advisory
- https://typo3.org/security/advisory/typo3-ext-sa-2020-017Vendor Advisory
- https://typo3.org/help/security-advisoriesVendor Advisory
- https://typo3.org/security/advisory/typo3-ext-sa-2020-017Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-25026?
How severe is CVE-2020-25026?
How do I fix CVE-2020-25026?
Are you affected by CVE-2020-25026?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
