Authorization Bypass Through User-Controlled Key in alfio-event/alf.io
CVE-2023-2260
8.8HIGH
What is CVE-2023-2260?
The authorization bypass vulnerability in Alf.io allows attackers to exploit user-controlled keys, potentially gaining unauthorized access to sensitive functionalities. This weakness affects versions prior to 2.0-M4-2304, emphasizing the need for users to update their systems to the latest version to mitigate potential risks.
Affected Version(s)
alfio-event/alf.io < 2.0-M4-2304