CVE-2024-25627 — Alf.io is a free and open source event attendance management system. An administrator on the alf.io application is able to upload HTML files that trigger JavaScript payloads. As such, an attacker gain — CVE Database · The Intelligence Room