{"id":"CVE-2020-25026","details":"The sf_event_mgt (aka Event management and registration) extension before 4.3.1 and 5.x before 5.1.1 for TYPO3 allows Information Disclosure (participant data, and event data via email) because of Broken Access Control.","aliases":["GHSA-g8rg-7rpr-cwr2"],"modified":"2026-04-12T00:36:51.802601Z","published":"2020-09-02T17:15:12.533Z","references":[{"type":"ADVISORY","url":"https://typo3.org/help/security-advisories"},{"type":"ADVISORY","url":"https://typo3.org/security/advisory/typo3-ext-sa-2020-017"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/derhansen/sf_event_mgt","events":[{"introduced":"0"},{"fixed":"9c8315aee5707d7dd000420bff9204ae96ef2ce7"},{"introduced":"a97a1c085f3ec66325da1a8bd90bb8e00c40ea33"},{"fixed":"17edcbf608b252cc1123e1279f0735f6aa28fef4"}],"database_specific":{"source":"CPE_FIELD","extracted_events":[{"introduced":"0"},{"fixed":"4.3.1"},{"introduced":"5.0.0"},{"fixed":"5.1.1"}],"cpe":"cpe:2.3:a:derhansen:event_management_and_registration:*:*:*:*:*:typo3:*:*"}}],"versions":["0.5.3","1.0.0","1.0.1","1.1.0","1.1.1","1.2.0","1.3.0","1.3.1","1.4.0","1.4.1","1.5.0","1.5.1","1.6.0","1.6.1","1.7.0","1.7.1","1.8.0","2.0.0","2.1.0","3.0.0","3.0.1","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","4.0.0","4.0.1","4.1.0","4.1.1","4.1.2","4.1.3","4.2.0","4.2.1","4.2.2","4.3.0","5.0.0","5.0.1","5.1.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-25026.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}