Vulnerabilities > CVE-2020-25026 - Incorrect Authorization vulnerability in Derhansen Event Management and Registration

047910
CVSS 4.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
derhansen
CWE-863

Summary

The sf_event_mgt (aka Event management and registration) extension before 4.3.1 and 5.x before 5.1.1 for TYPO3 allows Information Disclosure (participant data, and event data via email) because of Broken Access Control.

Vulnerable Configurations

Part Description Count
Application
Derhansen
45

Common Weakness Enumeration (CWE)