Impact
Hi.Events versions before 1.11.0 omit server‑side visibility checks, letting an attacker send order creation requests that reference hidden product and price identifiers. Because no authentication or authorization is performed, the attacker can buy tickets that are meant to remain private, such as VIP, invite‑only, or heavily discounted items, leading to revenue loss and potential misuse of premium access. The flaw maps to Missing Authorization (CWE‑862).
Affected Systems
The vulnerability affects all instances of Hi.Events deployed with a version older than 1.11.0, including the beta and release candidates preceding that milestone. The issue is active against the order creation API endpoint exposed by the Hi.Events application.
Risk and Exploitability
The CVSS score of 6.9 grades the issue as moderate, while the EPSS score of less than 1% indicates a very low likelihood of real‑world exploitation at the present moment. The flaw is not listed in the CISA KEV catalog. Attackers would exploit the defect by sending crafted POST requests to the order creation endpoint without needing any credentials; enumeration of sequential hidden ticket IDs is trivial once a valid hidden ID is discovered.
OpenCVE Enrichment