CVE-2026-57960
HiEventsDev Hi.Events 취약점
Hi.Events through 1.9.0 public check-in list endpoints use short_id as sole access control, allowing unauthenticated access to retrieve full attendee lists including emails and personal information. Attackers with knowledge of the short_id can call GET /api/public/check-in-lists/{short_id}/attendees to read attendee data and create or delete check-in records without authentication.
- 대응 우선순위
- 점검
- CVSS
- 8.3
- EPSS
- 0.34% 백분위 26.2% · 2026.07.20 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.06.30