Impact
The Event Booking extension for Joomla exposes a front‑end endpoint that allows user enumeration due to missing CSRF protection (CWE‑352). An attacker can submit requests that reveal the usernames or identities of registered users for events. The vulnerability enables information disclosure, potentially aiding credential harvesting or social engineering. The weakness lies in lack of request validation and CSRF checks rather than authentication or authorization deficiencies.
Affected Systems
The vulnerability affects any site using the joomdonation.com Events Booking extension for Joomla with a version earlier than 5.8.0. If the site has not upgraded past this boundary, it remains exposed until the defect is remedied. Sites using version 5.8.0 or newer are not impacted.
Risk and Exploitability
The CVSS score of 8.8 classifies this as a high‑severity flaw, indicating that exploitation could result in significant information disclosure, such as revealing user identities for event registrations. The EPSS score of <1% indicates a low but non‑zero probability of exploitation in the wild. The issue is not listed in the CISA KEV catalog, so it has not yet been confirmed as a known exploited vulnerability. Attackers would most likely target publicly accessible Joomla sites still running the affected extension, leveraging the lack of CSRF checks to discover usernames or identities of event participants. Because no prior authentication or elevated privileges are required, the risk remains elevated even if the likelihood of exploitation is modest.
OpenCVE Enrichment