📦 Alf

by Alf

🔍 What is Alf?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-45300

HIGH CVSS 7.5 Sep 6, 2024

A race condition vulnerability in alf.io allows attackers to bypass promo code usage limits by exploiting timing gaps between validation and enforcement. This affects all alf.io deployments prior to v...

CVE-2024-25634

HIGH CVSS 7.2 Feb 19, 2024

This vulnerability in alf.io ticket reservation system allows attackers to access email logs from other organizers' events through specially crafted requests. It affects all alf.io installations prior...

CVE-2024-25628

HIGH CVSS 7.6 Feb 16, 2024

This vulnerability allows users who should have been invalidated or deleted to retain access to the admin area in Alf.io event management systems. This affects all Alf.io deployments running vulnerabl...

CVE-2023-2258

HIGH CVSS 8.8 Apr 24, 2023

This vulnerability allows CSV formula injection attacks in alf.io event management software. Attackers can embed malicious formulas in CSV files that execute when opened in spreadsheet applications li...

CVE-2023-2260

HIGH CVSS 8.8 Apr 24, 2023

This CVE describes an authorization bypass vulnerability in alf.io event management software where attackers can manipulate user-controlled keys to access unauthorized resources. It affects all users ...