PT-2026-60804 · Fossasia+1 · Open-Event-Server
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Open Event Server versions prior to 1.19.2
Description
A missing authentication flaw allows unauthenticated attackers to export the complete member roster of any group, including names, email addresses, roles, and join dates. This is possible because the group followers CSV export endpoint lacks an authentication decorator. An attacker can use brute-force to enumerate sequential group IDs, trigger an export via an unauthenticated POST endpoint, and poll an unauthenticated task status endpoint to obtain a download URL for the member CSV.
Recommendations
Update to version 1.19.2 or later.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open-Event-Server