Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7hfj-8497-9m6v

Опубликовано: 22 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information.

The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information.

EPSS

Процентиль: 14%
0.00232
Низкий

7.5 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 7.5
nvd
21 день назад

Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information.

EPSS

Процентиль: 14%
0.00232
Низкий

7.5 High

CVSS3

Дефекты

CWE-284