Impact
The Joomla extension Events Booking – versions 5.0.0 through 5.8.1 – contains an ACL enforcement flaw that fails to verify whether the requesting user is permitted to download invoice information. This oversight results in an information‑disclosure vulnerability, allowing an attacker to retrieve confidential financial details that should be restricted to authorized personnel. The flaw is a classic example of insecure privilege management (CWE‑284).
Affected Systems
Systems installing the Events Booking extension for Joomla from joomdonation.com, specifically versions 5.0.0 up to 5.8.1, are vulnerable. Any deployment using these legacy versions without a patch is at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates a medium‑to‑high severity, while the EPSS probability of <1% suggests that exploitation is currently uncommon but still plausible. The vulnerability is not listed in CISA’s KEV catalog, yet it can be triggered via a standard web request to the invoice‑download functionality, potentially even by authenticated users lacking the proper role. Attackers could exfiltrate sensitive billing and customer data, compromising confidentiality and possibly supporting further social engineering or fraud.
OpenCVE Enrichment