CVE-2024-24751

sf_event_mgt is an event management and registration extension for the TYPO3 CMS based on ExtBase and Fluid. In affected versions the existing access control check for events in the backend module got broken during the update of the extension to TYPO3 12.4, because the `RedirectResponse` from the `$this->redirect()` function was never handled. This issue has been addressed in version 7.4.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:derhansen:event_management_and_registration:7.0.0:*:*:*:*:typo3:*:*

History

21 Nov 2024, 08:59

Type Values Removed Values Added
References () https://github.com/derhansen/sf_event_mgt/commit/a08c2cd48695c07e462d15eeb70434ddc0206e4c - Patch () https://github.com/derhansen/sf_event_mgt/commit/a08c2cd48695c07e462d15eeb70434ddc0206e4c - Patch
References () https://github.com/derhansen/sf_event_mgt/security/advisories/GHSA-4576-pgh2-g34j - Vendor Advisory () https://github.com/derhansen/sf_event_mgt/security/advisories/GHSA-4576-pgh2-g34j - Vendor Advisory
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 4.3

18 Oct 2024, 18:13

Type Values Removed Values Added
CPE cpe:2.3:a:derhansen:event_management_and_registration:7.0.0:*:*:*:*:typo3:*:*
First Time Derhansen
Derhansen event Management And Registration
CVSS v2 : unknown
v3 : 4.3
v2 : unknown
v3 : 8.8
References () https://github.com/derhansen/sf_event_mgt/commit/a08c2cd48695c07e462d15eeb70434ddc0206e4c - () https://github.com/derhansen/sf_event_mgt/commit/a08c2cd48695c07e462d15eeb70434ddc0206e4c - Patch
References () https://github.com/derhansen/sf_event_mgt/security/advisories/GHSA-4576-pgh2-g34j - () https://github.com/derhansen/sf_event_mgt/security/advisories/GHSA-4576-pgh2-g34j - Vendor Advisory
Summary
  • (es) sf_event_mgt es una extensión de registro y gestión de eventos para TYPO3 CMS basada en ExtBase y Fluid. En las versiones afectadas, la verificación de control de acceso existente para eventos en el módulo backend se rompió durante la actualización de la extensión a TYPO3 12.4, porque la función `RedirectResponse` de la función `$this->redirect()` nunca se manejó. Este problema se solucionó en la versión 7.4.0. Se recomienda a los usuarios que actualicen. No se conocen workarounds para esta vulnerabilidad.

13 Feb 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-13 19:15

Updated : 2024-11-21 08:59


NVD link : CVE-2024-24751

Mitre link : CVE-2024-24751

CVE.ORG link : CVE-2024-24751


JSON object : View

Products Affected

derhansen

  • event_management_and_registration
CWE
CWE-284

Improper Access Control

CWE-863

Incorrect Authorization