CVE-2026-63047
joomdonation.com · Events Booking extension for Joomla
The Events Booking extension for Joomla prior to version 5.8.2 fails to properly verify authorization for downloading invoice information.
Executive summary
An improper access control vulnerability in the Events Booking extension for Joomla allows unauthorized access to sensitive invoice data.
Vulnerability
This is an improper access control vulnerability where the extension fails to verify if an actor is authorized to download invoice information. This allows an unauthenticated remote attacker to access and download invoices, potentially exposing personally identifiable information.
Business impact
The vulnerability carries a CVSS score of 7.5, indicating a high severity risk. Successful exploitation results in unauthorized access to sensitive customer data, which can lead to significant privacy violations, regulatory non-compliance, and reputational damage for the organization.
Remediation
Immediate Action: Update the Events Booking extension for Joomla to version 5.8.2 or later.
Proactive Monitoring: Review web server and application access logs for unusual patterns of direct access to invoice download endpoints or high volumes of requests from single IP addresses.
Compensating Controls: Implement WAF rules to restrict access to invoice download URLs and ensure that only authenticated, authorized users can reach these paths.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations using the Events Booking extension must prioritize upgrading to version 5.8.2 to close this access control gap. Protecting customer PII is paramount, and this update is necessary to prevent unauthorized data exfiltration.