CVE-2026-60025

8.8

joomdonation.com · Events Booking extension for Joomla

The Joomla Events Booking extension prior to version 5.8.0 contains an unauthenticated frontend file upload endpoint lacking Cross-Site Request Forgery protection.

Executive summary

A high-severity Cross-Site Request Forgery vulnerability in the Events Booking extension for Joomla allows attackers to leverage unprotected frontend endpoints, posing severe risks to data integrity and system control.

Vulnerability

This flaw involves CWE-352 Cross-Site Request Forgery, specifically manifesting as an unprotected frontend file upload endpoint that requires user interaction and no privileges from a network vector.

Business impact

A successful exploit can lead to total technical impact, allowing attackers to compromise confidentiality, integrity, and availability within the environment. With a CVSS score of 8.8, the severity is classified as high, translating to potential unauthorized file uploads, full system compromise, and significant reputational damage if leveraged in targeted attacks against organization web assets.

Remediation

Immediate Action: Update the joomdonation.com Events Booking extension for Joomla to version 5.8.0 or later as soon as possible.

Proactive Monitoring: Monitor web server access logs for anomalous file upload attempts originating from frontend vectors and review user interaction patterns on the Joomla instance.

Compensating Controls: Deploy Web Application Firewall rules to inspect and block incoming requests targeting frontend file upload endpoints lacking valid anti-CSRF tokens.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the potential for total technical impact, organizations must prioritize upgrading the Events Booking extension to the fixed version. Immediate application of vendor updates is essential to mitigate the risk of unauthorized administrative actions and file uploads via Cross-Site Request Forgery vectors.

More joomdonation.com CVEs

Sources

Originally found and disclosed by Phil Taylor, mysites.guru, per the CVE Program record.