CyberRota Analysis
AI-GeneratedThe vulnerability allows users with frontend event management access to create events that are incorrectly attributed to other organizers, bypassing proper permission checks. This could lead to unauthorized event management and potential misuse of organizer records. Organizations utilizing the affected frontend management plugin should prioritize addressing this issue to prevent unauthorized access and maintain the integrity of event management.
Original NVD Description
The frontend management plugin attributed a newly created event to the submitting user's organizer record only when the request supplied no organizer of its own. The accompanying permission check confirmed only that the submitting user held any organizer role. A user with frontend event management access could therefore create an event that is attributed to another organizer.