derhansen/sf_event_mgt vulnerable to Broken Access Control in Backend Module
Moderate severity
GitHub Reviewed
Published
Feb 13, 2024
in
derhansen/sf_event_mgt
•
Updated Oct 18, 2024
Package
Affected versions
>= 7.0.0, < 7.4.0
Patched versions
7.4.0
Description
Published to the GitHub Advisory Database
Feb 13, 2024
Reviewed
Feb 13, 2024
Published by the National Vulnerability Database
Feb 13, 2024
Last updated
Oct 18, 2024
The existing access control check for events in the backend module got broken during the update of the extension to TYPO3 12.4, because the
RedirectResponse
from the$this->redirect()
function was never handled.References