Description
Hi.Events before 1.11.0 contains a missing server-side visibility enforcement vulnerability that allows unauthenticated attackers to purchase hidden tickets by referencing hidden product and price IDs in order creation requests without authorization checks. Attackers can enumerate sequential hidden ticket IDs from visible ones and submit order creation requests referencing those IDs to purchase VIP, invite-only, or discounted tickets intentionally withheld from public sale.
Published: 2026-07-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Hi.Events versions before 1.11.0 omit server‑side visibility checks, letting an attacker send order creation requests that reference hidden product and price identifiers. Because no authentication or authorization is performed, the attacker can buy tickets that are meant to remain private, such as VIP, invite‑only, or heavily discounted items, leading to revenue loss and potential misuse of premium access. The flaw maps to Missing Authorization (CWE‑862).

Affected Systems

The vulnerability affects all instances of Hi.Events deployed with a version older than 1.11.0, including the beta and release candidates preceding that milestone. The issue is active against the order creation API endpoint exposed by the Hi.Events application.

Risk and Exploitability

The CVSS score of 6.9 grades the issue as moderate, while the EPSS score of less than 1% indicates a very low likelihood of real‑world exploitation at the present moment. The flaw is not listed in the CISA KEV catalog. Attackers would exploit the defect by sending crafted POST requests to the order creation endpoint without needing any credentials; enumeration of sequential hidden ticket IDs is trivial once a valid hidden ID is discovered.

Generated by OpenCVE AI on July 31, 2026 at 10:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Hi.Events application to version 1.11.0 or later, which implements proper server‑side visibility enforcement on the order creation endpoint.
  • If an upgrade is not immediately possible, enforce authentication or API‑key validation on the order creation endpoint so that only authorized requests can reference hidden product identifiers.
  • As a temporary measure, implement network‑level restrictions or rate limiting on the order creation API to avoid automated enumeration attempts.

Generated by OpenCVE AI on July 31, 2026 at 10:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Hi.events
Hi.events hi.events
CPEs cpe:2.3:a:hi.events:hi.events:*:*:*:*:*:*:*:*
Vendors & Products Hi.events
Hi.events hi.events

Tue, 14 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Hi.Events through v1.10.0-beta contains a missing server-side visibility enforcement vulnerability that allows unauthenticated attackers to purchase hidden tickets by referencing hidden product and price IDs in order creation requests without authorization checks. Attackers can enumerate sequential hidden ticket IDs from visible ones and submit order creation requests referencing those IDs to purchase VIP, invite-only, or discounted tickets intentionally withheld from public sale. Hi.Events before 1.11.0 contains a missing server-side visibility enforcement vulnerability that allows unauthenticated attackers to purchase hidden tickets by referencing hidden product and price IDs in order creation requests without authorization checks. Attackers can enumerate sequential hidden ticket IDs from visible ones and submit order creation requests referencing those IDs to purchase VIP, invite-only, or discounted tickets intentionally withheld from public sale.
Title Hi.Events v1.10.0-beta Hidden Ticket Enumeration via Order Creation Endpoint Hi.Events < 1.11.0 Hidden Ticket Enumeration via Order Creation Endpoint

Tue, 14 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Hieventsdev
Hieventsdev hi.events
Vendors & Products Hieventsdev
Hieventsdev hi.events

Tue, 14 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description Hi.Events through v1.10.0-beta contains a missing server-side visibility enforcement vulnerability that allows unauthenticated attackers to purchase hidden tickets by referencing hidden product and price IDs in order creation requests without authorization checks. Attackers can enumerate sequential hidden ticket IDs from visible ones and submit order creation requests referencing those IDs to purchase VIP, invite-only, or discounted tickets intentionally withheld from public sale.
Title Hi.Events v1.10.0-beta Hidden Ticket Enumeration via Order Creation Endpoint
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Hi.events Hi.events
Hieventsdev Hi.events
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-15T15:42:42.390Z

Reserved: 2026-07-08T13:27:53.031Z

Link: CVE-2026-60118

cve-icon Vulnrichment

Updated: 2026-07-15T15:42:30.881Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T10:15:06Z

Weaknesses