CVE-2026-77128

Summary

The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthenticated remote user can pass a demand-override parameter to view hidden or time-restricted events, unless the disableOverrideDemand plugin setting is active. Exploitation of this issue requires only that disableOverrideDemand is not enabled.

Affected Software

VendorProductVersion RangeStatus
TYPO3Extension “Event management and registration”9.0.0 < 9.0.3affected
TYPO3Extension “Event management and registration”8.0.0 < 8.6.2affected
TYPO3Extension “Event management and registration”7.0.0 < 7.9.3affected
TYPO3Extension “Event management and registration”6.0.0 < 6.7.2affected
TYPO3Extension “Event management and registration”0 < 5.9.3affected

Weaknesses

  • CWE-862: CWE-862 Missing Authorization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References