What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in AwesomeTOGI Awesome Event Booking awesome-event-booking allows Cross Site Request Forgery.This issue affects Awesome Event Booking: from n/a through <= 2.7.5.
Explanation of Vulnerability in Simple Terms
02Summary
Awesome Event Booking versions 2.7.5 and earlier are vulnerable to cross-site request forgery (CSRF). An attacker can craft a malicious webpage that, when visited by a logged-in site administrator, performs unwanted actions on the booking system without the admin's knowledge or consent. The attacker has no special privileges and relies on the victim clicking a link or visiting a page.
What an attacker can do
03Attacker Capabilities
Perform unwanted actions on the booking system by tricking a logged-in admin into visiting a malicious webpage.
Potential impact on your site
04Site Impact
An attacker can modify booking settings, create fake bookings, or alter event data if an admin visits a malicious link.
Conditions required to exploit
05Prerequisites
A logged-in site administrator must visit a webpage controlled by the attacker.
Key dates
06Disclosure timeline
March 27, 2025
CVE published
April 28, 2026
Record updated