CVE-2024-24751

sf_event_mgt is an event management and registration extension for the TYPO3 CMS based on ExtBase and Fluid. In affected versions the existing access control check for events in the backend module got broken during the update of the extension to TYPO3 12.4, because the `RedirectResponse` from the `$this->redirect()` function was never handled. This issue has been addressed in version 7.4.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Configurations

No configuration.

History

13 Feb 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-13 19:15

Updated : 2024-02-13 19:45


NVD link : CVE-2024-24751

Mitre link : CVE-2024-24751

CVE.ORG link : CVE-2024-24751


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control

CWE-863

Incorrect Authorization