Hi.Events < 1.11.0 Hidden Ticket Enumeration via Order Creation Endpoint
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 6.9epss 0.4%
probabilidade de exploração
0.4%top 66% das CVEs
exploração observada
nãonenhuma fonte reporta
Hi.Events before 1.11.0 contains a missing server-side visibility enforcement vulnerability that allows unauthenticated attackers to purchase hidden tickets by referencing hidden product and price IDs in order creation requests without authorization checks. Attackers can enumerate sequential hidden ticket IDs from visible ones and submit order creation requests referencing those IDs to purchase VIP, invite-only, or discounted tickets intentionally withheld from public sale.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Produtos afetados
HiEventsDev · Hi.EventsReferências
https://github.com/HiEventsDev/Hi.Events/commit/9eec95e6176f500b71bf633986243045ca78cefbhttps://github.com/HiEventsDev/Hi.Events/pull/1259https://github.com/HiEventsDev/Hi.Events/releases/tag/v.1.11.0-betahttps://github.com/HiEventsDev/Hi.Events/security/advisories/GHSA-2h54-cprv-vj74https://www.vulncheck.com/advisories/hi-events-beta-hidden-ticket-enumeration-via-order-creation-endpoint