Impact
A registered user who has permission to edit own events can submit a POST request in which the record ID of another user’s event and the creator ID of the attacker’s own user ID are combined. This allows the attacker to assume ownership of the target event or venue. The flaw is an authorization bypass that compromises the integrity of event data, potentially leading to the unauthorized disclosure or modification of schedule information and venue responsibilities. The weakness is documented as CWE-639, Authorization Bypass through User-Controlled Key.
Affected Systems
Joomla Event Manager extension for Joomla, provided by joomlaeventmanager.net. Versions prior to 5.0.1 are affected.
Risk and Exploitability
The vulnerability has a CVSS score of 5.1, indicating moderate severity. No EPSS value is available, and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack requires an authenticated user who can edit own events and the ability to craft a POST request with forged form fields, which is likely achievable through web interfaces or automated scripts. When exploited, an attacker can hijack control of events or venues belonging to other users.
OpenCVE Enrichment