Impact
The Joomla extension Events Booking for joomdonation.com suffers from an insecure default configuration that allows unauthenticated users to upload media assets. Because the upload interface accepts arbitrary files, a threat actor could place executable scripts or malicious content on the server, leading to remote code execution or cross‑site scripting, depending on how the uploaded files are subsequently handled. This weakness is identified as CWE‑1188, reflecting an improper default configuration that permits unsafe operations for unauthenticated users.
Affected Systems
The vulnerability affects the joomdonation.com Events Booking extension for Joomla, specifically any installation running a version lower than 5.8.0. No additional vendor or product variants are listed beyond the primary extension.
Risk and Exploitability
The CVSS score of 9.8 marks this flaw as critical, and the EPSS score of less than 1% indicates that, while exploitation is currently rare, the potential impact is high. The extension is not present in the CISA KEV catalog. The attack vector is inferred to involve submitting a media file through the public upload interface; no special authentication or other conditions are required, making exploitation straightforward for an attacker with network access to the Joomla site.
OpenCVE Enrichment