Executive brief
Hi.Events, an event management and ticketing platform, contains a flaw in how it processes promotional codes. An attacker can use a single-use or limited-use discount code an unlimited number of times by placing multiple orders before the system updates its internal usage counter. This can lead to significant financial losses for event organizers as attendees bypass payment requirements or use unauthorized discounts.
Technical details
A Time-of-Check Time-of-Use (TOCTOU) race condition exists in the promo code validation logic of Hi.Events. When an order is reserved, the system checks the 'order_usage_count' against the 'max_allowed_usages'; however, the counter is only incremented asynchronously via the 'UpdateEventStatisticsJob' after an order is fully completed. Because the 'CompleteOrderHandler' does not re-validate the promo code eligibility, an attacker can sequentially create multiple reservations using the same code while the counter remains stale. This allows for unlimited redemptions of restricted codes without requiring high-concurrency exploitation. The vulnerability is present in versions up to and including 1.9.0.
Affected products
- HiEventsDev Hi.Events through 1.9.0
Timeline
- 2026-05-24: other: Vulnerability reported to vendor via email
- 2026-06-17: disclosed: Public issue opened on GitHub repository
- 2026-06-29: advisory: CVE published and added to NVD