CyberRota Analysis
AI-GeneratedThe Joomla Event Manager extension prior to version 5.0.1 is vulnerable to cross-user event and venue takeover, allowing a registered user with edit-own rights to manipulate form fields and gain unauthorized access to another user's records. This could lead to unauthorized modifications or control over events, posing a risk to event integrity and user data. Joomla site administrators and developers using this extension should prioritize applying the latest update to mitigate this vulnerability.
Original NVD Description
Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user's record id together with their own id as created_by and take over that record.