Skip to main content

Vendor/product archive

alf / alf CVEs

Beta · best-effort

9 CVEs tagged to alf / alf0 Critical, 7 High, 1 Medium, 1 Low, 0 Unrated.

CVE-2024-45300

Published Sep 6, 2024

alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5, a race condition allows the user to bypass the li…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45299

Published Sep 6, 2024

alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5, the preloaded data as json is not escaped correct…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25635

Published Feb 19, 2024

alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, organization owners can view the generated API KEY and USERS of other organization owners using t…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-25634

Published Feb 19, 2024

alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, an attacker can access data from other organizers. The attacker can use a specially crafted reque…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-25628

Published Feb 16, 2024

Alf.io is a free and open source event attendance management system. In versions prior to 2.0-M4-2402 users can access the admin area even after being invalidated/deleted. This is…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-25627

Published Feb 16, 2024

Alf.io is a free and open source event attendance management system. An administrator on the alf.io application is able to upload HTML files that trigger JavaScript payloads. As s…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-2260

Published Apr 24, 2023

Authorization Bypass Through User-Controlled Key in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-2259

Published Apr 24, 2023

Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-2258

Published Apr 24, 2023

Improper Neutralization of Formula Elements in a CSV File in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1