CVE-2024-38874: TYPO3 EVENTS2

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue was discovered in the events2 (aka Events 2) extension before 8.3.8 and 9.x before 9.0.6 for TYPO3. Missing access checks in the management plugin lead to an insecure direct object reference (IDOR) vulnerability with the potential to activate or delete various events for unauthenticated users.

Affected products

  • TYPO3 EVENTS2: before 8.3.8 (fixed in 8.3.8); from 9.0, before 9.0.6 (fixed in 9.0.6)

Published 2024-06-21. Last modified 2026-06-17.