haitam lazaar / lazaarsec
← Back to CVE Registry
CVE-2026-14842unrated[patched]

Unauthenticated Payment Bypass via Token Detachment

TARGET ECOSYSTEM / VENDOREvents Made Easy
AFFECTED PRODUCTEvents Made Easy (< 3.1.2)
CWE CLASSIFICATIONCWE-284: Improper Access Control
PUBLISHED DATE2026-07-07

Summary

Events Made Easy (< 3.1.2) does not properly bind the payment authorization token to the specific payment record being charged. This allows an unauthenticated attacker to pay a low amount for a cheap booking while manipulating the request to have a separate, higher-priced booking marked as fully paid.

Official Status

  • CNA Rating: Unrated
  • Impact: Unauthenticated Payment Bypass
  • Fixed Version: 3.1.2