vendor:
Joomla! com_booking
by:
qw3rTyTy
7.5
CVSS
HIGH
Information Leak
200
CWE
Product Name: Joomla! com_booking
Affected Version From: 2.4.2009
Affected Version To: 2.4.2009
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Slackware/Nginx/Joomla! 3.10.11
2023
Joomla! com_booking component 2.4.9 – Information Leak (Account enumeration)
The Joomla! com_booking component version 2.4.9 allows an attacker to enumerate all accounts by performing a GET request with a specific ID parameter.
Mitigation:
Upgrade to a patched version or apply a fix provided by the vendor.