What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Server Side Include (SSI) Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through <= 2.3.11.
Explanation of Vulnerability in Simple Terms
02Summary
Event Tickets with Ticket Scanner versions up to 2.3.11 contain a privilege escalation vulnerability. An authenticated user with low privileges can modify data across the application and affect system availability. The vulnerability has a wide attack surface due to changed scope, meaning impacts extend beyond the vulnerable component itself.
What an attacker can do
03Attacker Capabilities
Modify application data, read sensitive information, and disrupt service availability.
Potential impact on your site
04Site Impact
Authenticated users can escalate privileges to alter event data, access confidential information, and cause downtime.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account on the site.
Key dates
06Disclosure timeline
November 18, 2024
CVE published
May 11, 2026
Record updated