PT-2026-53678 · Hi.Events · Hi.Events
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Hi.Events versions prior to 1.9.1
Description
Public check-in list endpoints rely exclusively on the
short id for access control, which enables unauthenticated users to retrieve complete attendee lists containing emails and personal information. An attacker who possesses the short id can access the endpoint 'GET /api/public/check-in-lists/{short id}/attendees' to read attendee data and perform unauthorized creation or deletion of check-in records.Recommendations
Update to a version newer than 1.9.0.
Restrict access to the 'GET /api/public/check-in-lists/{short id}/attendees' endpoint to minimize the risk of unauthorized data retrieval.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hi.Events