CVE-2023-54357Disclosure(artio / book_it\!)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch artio book_it\! systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Joomla com_booking component 2.4.9 contains an information disclosure vulnerability that allows unauthenticated attackers to enumerate user accounts by exploiting the getUserData function in the customer controller. Attackers can send GET requests to index.php with option=com_booking, controller=customer, task=getUserData, and an id parameter to retrieve user names, usernames, and email addresses through brute force enumeration.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-203

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • book_it\!

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-20); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
book_it\!

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-06-19: 1Mentions · 2026-06-20: 2Mentions · 2026-08-30: 1Patch / Workaround · 2026-08-30: 1Technical Details · 2026-06-19: 1Technical Details · 2026-06-20: 2Technical Details · 2026-08-30: 106-1906-2008-30
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-191
Disclosure1
2026-06-202
Disclosure2
2026-08-301
Patch1
Full discourse4 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH severity CVE-2023-54357 (CVSS 7.5) affects Joomla com_booking 2.4.9. Unauthenticated attackers can enumerate user accounts via getUserData function. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/nGdQPa94of

    Post summary

    CVE-2023-54357, a high‑severity Jooma com_booking 2.4.9 vulnerability allowing unauthenticated user enumeration via getUserData, is disclosed with an urgent patch recommendation.

    0000037
    122 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2023-54357 Joomla com_booking component 2.4.9 contains an information disclosure vulnerability that allows unauthenticated attackers to enumerate user accounts by exploiting the… https://www.cve.org/CVERecord?id=CVE-2023-54357 ----- Traducción: CVE-2023-54357 Joo… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2023-54357, describing an information disclosure flaw in Joomla's com_booking component v2.4.9 that allows unauthenticated enumeration of user accounts, without referencing any PoC, exploits, patches, or active attacks.

    0000036
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2023-54357 Joomla com_booking component 2.4.9 contains an information disclosure vulnerability that allows unauthenticated attackers to enumerate user accounts by exploiting the… https://www.cve.org/CVERecord?id=CVE-2023-54357

    Post summary

    CVE-2023-54357 exposes an information‑disclosure flaw in Joomla’s com_booking component 2.4.9 that allows unauthenticated attackers to enumerate user accounts.

    00000272
    57.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2023-54357 Information Disclosure in Joomla com_booking Component 2.4.9 via getUserData Function https://vulmon.com/vulnerabilitydetails?qid=CVE-2023-54357

    Post summary

    The text provides a concise disclosure of CVE‑2023‑54357, noting an information disclosure issue in Joomla's com_booking component.

    0000045
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appartiobook_it\!2.4.9joomla\!-

Explore more