What the vulnerability does
01Description
Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user's record id together with their own id as created_by and take over that record.
Explanation of Vulnerability in Simple Terms
02Summary
JEM - Joomla Event Manager contains an authorization bypass vulnerability in how it validates user-controlled keys. An authenticated administrator can manipulate request parameters to bypass access controls and modify data they should not have permission to change. The vulnerability requires high-level privileges to exploit and has limited integrity impact.
What an attacker can do
03Attacker Capabilities
Modify event data or settings beyond their authorized scope by manipulating request parameters.
Potential impact on your site
04Site Impact
Administrators with malicious intent or compromised admin accounts can alter event information without proper authorization checks.
Conditions required to exploit
05Prerequisites
Attacker must have administrator-level access to the Joomla site.
Key dates
06Disclosure timeline
August 27, 2026
CVE published