Insecure Direct Object Reference (IDOR) Vulnerability in TYPO3 Events 2 Extension
CVE-2024-38874

5.4MEDIUM

Key Information:

Vendor

TYPO3

Vendor
CVE Published:
21 June 2024

What is CVE-2024-38874?

An issue was discovered in the events2 (aka Events 2) extension before 8.3.8 and 9.x before 9.0.6 for TYPO3. Missing access checks in the management plugin lead to an insecure direct object reference (IDOR) vulnerability with the potential to activate or delete various events for unauthenticated users.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.