Executive brief
Events Booking is a popular Joomla extension used to manage event registrations and payments. A security flaw in versions 5.0 through 5.8.1 allows unauthorized users to download invoice information that they should not have access to. This could lead to the exposure of sensitive customer billing details and transaction records.
Technical details
An improper access control vulnerability (CWE-284) exists in the Events Booking extension for Joomla in versions 5.0 through 5.8.1. The application fails to adequately validate that the requesting actor has the necessary permissions to access and download specific invoice records. An attacker could potentially exploit this by directly accessing invoice download links or manipulating parameters to view billing data belonging to other registrants. The issue is addressed in versions following 5.8.1.
Affected products
- joomdonation.com Events Booking extension for Joomla 5.0-5.8.1
Timeline
- 2026-07-22: advisory: NVD publication date