haitam lazaar / lazaarsec
← Back to CVE Registry
CVE-2026-148435.3medium[patched]

Unauthenticated Person Data Modification via IDOR

TARGET ECOSYSTEM / VENDOREvents Made Easy
AFFECTED PRODUCTEvents Made Easy (< 3.1.4)
CWE CLASSIFICATIONCWE-639: Insecure Direct Object Reference
PUBLISHED DATE2026-07-13

Summary

Events Made Easy (< 3.1.4) does not verify that the requester is authorized to modify the targeted record when handling an unauthenticated data-change request. It relies only on a public nonce with no per-record token or ownership check, allowing unauthenticated attackers to overwrite the personal data of any person record.