CVE-2024-38874 Information
Jun 22, 2024
cve
Description
An issue was discovered in the events2 (aka Events 2) extension before 8.3.8 and 9.x before 9.0.6 for TYPO3. Missing access checks in the management plugin lead to an insecure direct object reference (IDOR) vulnerability with the potential to activate or delete various events for unauthenticated users.
Reference
https://typo3.org/security/advisory/typo3-ext-sa-2024-003
Share on: