PT-2026-53678 · Hi.Events · Hi.Events

·

CVE-2026-57960

·

Published

2026-06-29

·

Updated

2026-06-29

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Hi.Events versions prior to 1.9.1
Description Public check-in list endpoints rely exclusively on the short id for access control, which enables unauthenticated users to retrieve complete attendee lists containing emails and personal information. An attacker who possesses the short id can access the endpoint 'GET /api/public/check-in-lists/{short id}/attendees' to read attendee data and perform unauthorized creation or deletion of check-in records.
Recommendations Update to a version newer than 1.9.0. Restrict access to the 'GET /api/public/check-in-lists/{short id}/attendees' endpoint to minimize the risk of unauthorized data retrieval.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57960

Affected Products

Hi.Events