CVE-2020-25026

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/09/2020
Last modified:
21/07/2021

Description

The sf_event_mgt (aka Event management and registration) extension before 4.3.1 and 5.x before 5.1.1 for TYPO3 allows Information Disclosure (participant data, and event data via email) because of Broken Access Control.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:derhansen:event_management_and_registration:*:*:*:*:*:typo3:*:* 4.3.1 (excluding)
cpe:2.3:a:derhansen:event_management_and_registration:*:*:*:*:*:typo3:*:* 5.0.0 (including) 5.1.1 (excluding)