Description
Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection.
Published: 2026-07-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Event Booking extension for Joomla exposes a front‑end endpoint that allows user enumeration due to missing CSRF protection (CWE‑352). An attacker can submit requests that reveal the usernames or identities of registered users for events. The vulnerability enables information disclosure, potentially aiding credential harvesting or social engineering. The weakness lies in lack of request validation and CSRF checks rather than authentication or authorization deficiencies.

Affected Systems

The vulnerability affects any site using the joomdonation.com Events Booking extension for Joomla with a version earlier than 5.8.0. If the site has not upgraded past this boundary, it remains exposed until the defect is remedied. Sites using version 5.8.0 or newer are not impacted.

Risk and Exploitability

The CVSS score of 8.8 classifies this as a high‑severity flaw, indicating that exploitation could result in significant information disclosure, such as revealing user identities for event registrations. The EPSS score of <1% indicates a low but non‑zero probability of exploitation in the wild. The issue is not listed in the CISA KEV catalog, so it has not yet been confirmed as a known exploited vulnerability. Attackers would most likely target publicly accessible Joomla sites still running the affected extension, leveraging the lack of CSRF checks to discover usernames or identities of event participants. Because no prior authentication or elevated privileges are required, the risk remains elevated even if the likelihood of exploitation is modest.

Generated by OpenCVE AI on August 3, 2026 at 02:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Events Booking extension to version 5.8.0 or later
  • Disable or restrict the file upload interface until the patch is applied
  • Ensure that any remaining file upload functionality incorporates CSRF protection, such as session‑bound tokens
  • Limit write permissions to the upload directory to prevent execution of uploaded files

Generated by OpenCVE AI on August 3, 2026 at 02:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Joomdonation.com
Joomdonation.com events Booking Extension For Joomla
Vendors & Products Joomdonation.com
Joomdonation.com events Booking Extension For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection. Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection.

Mon, 20 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Description The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection.
Title Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0
Weaknesses CWE-352
References

Subscriptions

Joomdonation.com Events Booking Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-23T14:55:59.397Z

Reserved: 2026-07-08T05:31:35.889Z

Link: CVE-2026-60025

cve-icon Vulnrichment

Updated: 2026-07-20T19:34:05.206Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T03:00:04Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)