The CVE-2026-72547 record indicates an insecure direct object reference vulnerability in Attendize through commit 9289acb. This vulnerability allows authenticated event organisers to bulk import attendees into events belonging to other accounts without verifying ownership. The postImportAttendee endpoint is particularly susceptible to exploitation, enabling attackers to inject bulk attendee data into any [truncated]
An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event organiser to inject attendees and orders into events belonging to other accounts via the postInviteAttendee endpoint. The endpoint loads the target event by ID without scoping the query to the authenticated organiser account. This vulnerability enables attackers to modify event data and fin [truncated]
The CVE-2026-72690 record details an improper authorization vulnerability in Attendize, a software used for event management. This vulnerability, tracked as CVE-2026-72690, allows an authenticated remote attacker to inject persistent mandatory survey questions into another organizer's events. The issue arises from the postCreateEventQuestion method loading the target event without tenant-isolation scope, [truncated]