Executive brief
Joomla Event Manager is an open-source extension for Joomla that manages events, venues, calendars, and registrations. A vulnerability in versions before 5.0.1 allows any visitor with a session token to overwrite articles and force-publish them, potentially enabling unauthorized content modification or injection on event-related pages.
Technical details
The vulnerability is an authorization bypass in Joomla Event Manager's article handling. Any visitor holding their own session token can republish and overwrite articles associated with events without proper permission checks. The flaw affects versions prior to 5.0.1 and requires only that an attacker possess a valid session token (a low bar for unauthenticated or low-privilege users). Successful exploitation allows unauthorized content modification, defacement, or injection of malicious content into event-related articles. The vulnerability has been patched in version 5.0.1.
Affected products
- joomlaeventmanager.net Joomla Event Manager < 5.0.1
Timeline
- 2026-08-27: disclosed
- 2026-09-14: patched: Fixed in JEM 5.0.1