CyberRota Analysis
AI-GeneratedThe Joomla Event Manager extension prior to version 5.0.1 allows any logged-in user to access attendee lists, including names, usernames, registration dates, and statuses for events they do not manage, even for unpublished events. This vulnerability poses a risk of unauthorized information disclosure, which could lead to privacy concerns and potential misuse of attendee data. Joomla administrators and users of the affected extension should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1 - A non-manager can therefore read attendee names, usernames, registration dates and statuses for events they do not manage, including lists belonging to unpublished events.