SB2024062812 - Multiple vulnerabilities in Events 2 extension for TYPO3
Published: June 28, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Use of cache containing sensitive information (CVE-ID: N/A)
The vulnerability allows a remote attacker to compromise user accounts.
The vulnerability exists due to improper cache configuration for some actions. A remote user can gain access to cached data.
2) SQL injection (CVE-ID: N/A)
The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data within a LIKE comparison. A remote user can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.
Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.
3) Improper access control (CVE-ID: CVE-2024-38874)
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the management plugin. A remote user can cause insecure direct object reference (IDOR) issue and activate or delete various events.
Remediation
Install update from vendor's website.