Impact
A logged‑in visitor with a valid session token can overwrite and force‑publish event articles, allowing an attacker to alter event content or deface the site. This undermines the integrity of posted information and can enable malicious or false information to appear as legitimate events.
Affected Systems
The vulnerability affects the Joomla Event Manager extension from joomlaeventmanager.net, known as JEM. Versions earlier than 5.0.1 are vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. Because the flaw requires only a session token from any logged‑in user—not administrator privileges—the barrier to exploitation is relatively low if the attacker can obtain or simulate such a token. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers could exploit this by simply logging in with a normal user account and then modifying event articles, potentially for defacement or misinformation.
OpenCVE Enrichment