Back to overview

CVE-2023-54357

HIGH
7.5
CVSS 3.1
Description
Joomla com_booking component 2.4.9 contains an information disclosure vulnerability that allows unauthenticated attackers to enumerate user accounts by exploiting the getUserData function in the customer controller. Attackers can send GET requests to index.php with option=com_booking, controller=customer, task=getUserData, and an id parameter to retrieve user names, usernames, and email addresses through brute force enumeration.

Metadata

CVE ID
CVE-2023-54357
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-01-10 01:51 UTC
Published
2026-06-19 17:52 UTC
Last updated
2026-06-19 17:52 UTC
Primary CWE
CWE-203
Observable Discrepancy
Vendor / Product
Artio / Joomla! com_booking component
Sources
cve.org  ·  NVD

Severity & Metrics

7.5 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products (1)
VendorProductPlatformVersions
Artio Joomla! com_booking component 2.4.9
Weakness (CWE)
CWESourceDescription
CWE-203 cna Observable Discrepancy
CVSS scores (2)
ScoreSeverityVersionSourceVector
8.7 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
7.5 HIGH 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
References (4)
Back to overview