CVE-2023-54357: Joomla com_booking 2.4.9 Information Disclosure via Account Enumeration

Published Jun 19, 2026
·
Updated

Joomla combooking component 2.4.9 contains an information disclosure vulnerability that allows unauthenticated attackers to enumerate user accounts by exploiting the getUserData function in the customer controller. Attackers can send GET requests to index.php with option=combooking, controller=customer, task=getUserData, and an id parameter to retrieve user names, usernames, and email addresses through brute force enumeration.

Affected Software

2 affected components
Joomla com_booking=2.4.9
artio Book It\! Joomla\!=2.4.9

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove joomla/com_booking from your environment.

    Uninstall or remove the com_booking component if it is not required to eliminate the vulnerable endpoint (index.php?option=com_booking&controller=customer&task=getUserData).

  2. Configuration

    Disable the getUserData task in the customer controller or change its access control so it requires authentication, preventing unauthenticated GET requests to index.php?option=com_booking&controller=customer&task=getUserData.

    Joomla com_booking (customer controller) task=getUserData = disabled or require authentication
  3. Compensating control

    Deploy a WAF or firewall rule to block or rate-limit HTTP GET requests matching index.php with parameters option=com_booking, controller=customer, task=getUserData and an id parameter; restrict access to this endpoint to trusted IPs if possible.

  4. Operational

    Review web server and application logs for GET requests to index.php with option=com_booking, controller=customer, task=getUserData and id parameters; investigate and respond to any suspected account enumeration activity.

Event History

Jun 19, 2026
CVE Published
via MITRE·05:52 PM
Data Sourced
via MITRE·05:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2023-54357?

CVE-2023-54357 has a high severity rating of 7.5.

2

How does CVE-2023-54357 impact Joomla com_booking users?

CVE-2023-54357 allows unauthenticated attackers to enumerate user accounts, potentially exposing sensitive user information.

3

What versions of Joomla are affected by CVE-2023-54357?

CVE-2023-54357 specifically affects Joomla com_booking version 2.4.9.

4

How can I mitigate the risk from CVE-2023-54357?

To mitigate CVE-2023-54357, update the Joomla com_booking component to the latest version or disable the affected component.

5

Is authentication required to exploit CVE-2023-54357?

No, CVE-2023-54357 can be exploited by unauthenticated attackers, meaning no login credentials are needed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203