GHSA-g8rg-7rpr-cwr2
Information Disclosure in TYPO3 extension sf_event_mgt
Quick fix
GHSA-g8rg-7rpr-cwr2 — derhansen/sf_event_mgt: upgrade to the fixed version with the command below.
composer require derhansen/sf_event_mgt:^4.3.1Details
A missing access check in the backend module allows an authenticated backend user to export participant data for events which the user does not have access to, resulting in Information Disclosure.
Another missing access check in the backend module allows an authenticated backend user to send emails to event participants for events which the user does not have access to, resulting in Broken Access Control.
External reference: [https://typo3.org/security/advisory/typo3-ext-sa-2020-017](https://typo3.org/security/advisory/typo3-ext-sa-2020-017)
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 4.3.1composer require derhansen/sf_event_mgt:^4.3.15.0.0Fixed in: 5.1.1composer require derhansen/sf_event_mgt:^5.1.1References
- https://github.com/derhansen/sf_event_mgt/security/advisories/GHSA-g8rg-7rpr-cwr2[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2020-25026[ADVISORY]
- https://github.com/derhansen/sf_event_mgt/commit/17edcbf608b252cc1123e1279f0735f6aa28fef4[WEB]
- https://packagist.org/packages/derhansen/sf_event_mgt[WEB]
- https://typo3.org/help/security-advisories[WEB]
- https://typo3.org/security/advisory/typo3-ext-sa-2020-017[WEB]