CVE-2026-77129

Source
https://cve.org/CVERecord?id=CVE-2026-77129
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-77129.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-77129
Published
2026-08-25T09:00:44.104Z
Modified
2026-08-28T11:47:22.008190082Z
Severity
  • 7.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Server-Side Template Injection in extension "Event management and registration" (sf_event_mgt)
Details

The extension passes an editor-configurable email subject string directly into a Fluid template source without restriction. A backend user with edit access to the event plugin or Backend Module can supply Fluid ViewHelper syntax in this field to disclose sensitive data or execute TypoScript content objects. Exploitation of this issue requires an authenticated backend account with edit access to the event registration plugin or backend module.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77129.json",
    "cwe_ids": [
        "CWE-1336"
    ],
    "cna_assigner": "TYPO3"
}
References

Affected packages

Git / github.com/derhansen/sf_event_mgt

Affected ranges

Type
GIT
Repo
https://github.com/derhansen/sf_event_mgt
Events
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "9.0.0"
        },
        {
            "fixed": "9.0.3"
        },
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "8.6.2"
        },
        {
            "introduced": "7.0.0"
        },
        {
            "fixed": "7.9.3"
        },
        {
            "introduced": "6.0.0"
        },
        {
            "fixed": "6.7.2"
        },
        {
            "introduced": "0"
        },
        {
            "fixed": "5.9.3"
        }
    ]
}

Affected versions

0.*
0.5.3
1.*
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.*
2.0.0
2.1.0
3.*
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
4.*
4.0.0
4.0.1
4.1.0
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
5.*
5.0.0
5.0.1
5.1.0
5.1.1
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.6.0
5.6.1
5.7.0
5.8.0
5.9.0
5.9.1
5.9.2
6.*
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.2.3
6.2.4
6.3.0
6.3.1
6.4.0
6.4.1
6.5.0
6.5.1
6.5.2
6.5.3
6.6.0
6.6.1
6.6.2
6.7.0
6.7.1
7.*
7.0.0
7.1.0
7.1.1
7.1.2
7.1.3
7.2.0
7.3.0
7.3.1
7.3.2
7.4.0
7.4.1
7.4.2
7.4.3
7.5.0
7.5.1
7.6.0
7.7.0
7.8.0
7.8.1
7.9.0
7.9.1
7.9.2
8.*
8.0.0
8.0.1
8.1.0
8.1.1
8.2.0
8.3.0
8.4.0
8.5.0
8.5.1
8.5.2
8.5.4
8.6.0
8.6.1
9.*
9.0.0
9.0.1
9.0.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-77129.json"