Impact
A Joomla extension for iCagenda contains an access control bypass that permits a backend operator with only com_icagenda permissions to enumerate all Joomla user profiles. The flaw exposes usernames, email addresses and other profile information, representing an information disclosure vulnerability classified as CWE‑284. The description explicitly confirms that the enumeration ability is available to operators with restricted access, indicating that the privilege escalation leads directly to visibility of user data that should be protected.
Affected Systems
The vulnerability is present in the iCagenda extension for Joomla. Versions up to 4.0.11 appear to be affected, although the CVE description does not specify a lower bound. The vendor is icagenda.com. Any installation of iCagenda that has not been updated to a revision beyond 4.0.11 remains susceptible.
Risk and Exploitability
The CVSS score of 5.1 assigns the issue a medium severity rating, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been identified. Exploitability requires a Joomla backend account that already has com_icagenda scope; the likely attack vector therefore involves either the compromise of such an account or social engineering of a user with sufficient module permissions. If an attacker gains or is lent this access, they can enumerate all site users and collect sensitive data.
OpenCVE Enrichment