Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user's record id together with their own id as created_by and take over that record.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://www.joomlaeventmanager.net/ |
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-27 06:17
Updated : 2026-08-28 16:09
NVD link : CVE-2026-77035
Mitre link : CVE-2026-77035
CVE.ORG link : CVE-2026-77035
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
