Executive brief
Attendize is an open-source ticket selling and event management platform. An authenticated attacker who is an event organizer can inject attendees and fake orders into events owned by other accounts by exploiting a flaw in the event invitation endpoint. This allows cross-account manipulation of event data and financial records, potentially leading to fraudulent ticket sales, revenue loss, and data integrity violations.
Technical details
The vulnerability is an insecure direct object reference (IDOR) in the postInviteAttendee endpoint. The endpoint fails to scope its database query to the authenticated organizer's account when loading the target event by ID, allowing any authenticated organizer to reference and modify events belonging to other accounts. An authenticated attacker can craft requests to inject attendees and create orders for events they do not own, modifying both event data and financial records across account boundaries. The flaw is present through at least commit 9289acb. A patch may be available in later versions of Attendize.
Affected products
- Attendize Attendize through commit 9289acb
Timeline
- 2026-08-11: disclosed