Description
Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information.
Published: 2026-07-22
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Joomla extension Events Booking – versions 5.0.0 through 5.8.1 – contains an ACL enforcement flaw that fails to verify whether the requesting user is permitted to download invoice information. This oversight results in an information‑disclosure vulnerability, allowing an attacker to retrieve confidential financial details that should be restricted to authorized personnel. The flaw is a classic example of insecure privilege management (CWE‑284).

Affected Systems

Systems installing the Events Booking extension for Joomla from joomdonation.com, specifically versions 5.0.0 up to 5.8.1, are vulnerable. Any deployment using these legacy versions without a patch is at risk.

Risk and Exploitability

The CVSS score of 7.5 indicates a medium‑to‑high severity, while the EPSS probability of <1% suggests that exploitation is currently uncommon but still plausible. The vulnerability is not listed in CISA’s KEV catalog, yet it can be triggered via a standard web request to the invoice‑download functionality, potentially even by authenticated users lacking the proper role. Attackers could exfiltrate sensitive billing and customer data, compromising confidentiality and possibly supporting further social engineering or fraud.

Generated by OpenCVE AI on August 4, 2026 at 00:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Events Booking extension to a version later than 5.8.1 where the ACL check is corrected.
  • If an immediate upgrade is not feasible, enforce Joomla’s native ACL to deny invoice download permissions to non‑authorized roles, ensuring the extension cannot override these settings.
  • Validate that the restriction is effective by attempting to access the invoice download URL with a test account that should not have permission; confirm that access is denied.

Generated by OpenCVE AI on August 4, 2026 at 00:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Joomdonation.com
Joomdonation.com events Booking Extension For Joomla
Vendors & Products Joomdonation.com
Joomdonation.com events Booking Extension For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information. Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information.

Wed, 22 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Description The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information.
Title Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1
Weaknesses CWE-284
References

Subscriptions

Joomdonation.com Events Booking Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-23T15:00:12.897Z

Reserved: 2026-07-15T08:12:23.735Z

Link: CVE-2026-63047

cve-icon Vulnrichment

Updated: 2026-07-22T12:51:13.955Z

cve-icon NVD

Status : Deferred

Published: 2026-07-22T08:16:23.950

Modified: 2026-07-23T16:17:47.157

Link: CVE-2026-63047

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:15:04Z

Weaknesses