Insecure Direct Object Reference in Attendize Affects Event Management Functionality
CVE-2026-72546
7.1HIGH
What is CVE-2026-72546?
A vulnerability exists in Attendize that permits authenticated event organisers to exploit insecure direct object references through the postInviteAttendee endpoint. By forging requests, an attacker could manipulate event data and financial records by targeting events not belonging to their account. This flaw arises from the lack of proper query scoping to the authenticated organiser, enabling unauthorized access and modification of sensitive information across different user accounts.
Affected Version(s)
Attendize 0 <= 9289acb
