CyberRota Analysis
AI-GeneratedThe Events Booking extension for Joomla versions prior to 5.8.0 is vulnerable due to a frontend file upload endpoint that lacks proper CSRF protection, allowing attackers to exploit this weakness for user enumeration. This vulnerability could lead to unauthorized access or manipulation of user data, posing a significant risk to affected Joomla installations. Organizations using this extension should prioritize updating to version 5.8.0 or later to mitigate potential security threats.
Original NVD Description
Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection.