← Back to CVE Registry
CVE-2026-148435.3medium[patched]
Unauthenticated Person Data Modification via IDOR
TARGET ECOSYSTEM / VENDOREvents Made Easy
AFFECTED PRODUCTEvents Made Easy (< 3.1.4)
CWE CLASSIFICATIONCWE-639: Insecure Direct Object Reference
PUBLISHED DATE2026-07-13
ADVISORY / CNAWPScan Advisory (CNA) ↗
Summary
Events Made Easy (< 3.1.4) does not verify that the requester is authorized to modify the targeted record when handling an unauthenticated data-change request. It relies only on a public nonce with no per-record token or ownership check, allowing unauthenticated attackers to overwrite the personal data of any person record.