---
id: CVE-2023-54357
title: >-
  Joomla com_booking component 2.4.9 contains an information disclosure
  vulnerability that allows unauthenticated attackers to enumerate user accounts
  by exploiting the getUserData function in the customer controller
summary: >-
  Joomla com_booking component 2.4.9 contains an information disclosure
  vulnerability that allows unauthenticated attackers to enumerate user accounts
  by exploiting the getUserData function in the customer controller. Attackers
  can send GE…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-203
vendor: artio
product: book_it!
affected:
  - book_it! = 2.4.9
published: '2026-06-19'
updated: '2026-08-21'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-54357'
references:
  - url: 'http://www.artio.net/'
    label: disclosure@vulncheck.com
  - url: 'http://www.artio.net/downloads/joomla/book-it/book-it-2-free/download'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/51595'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/joomla-com-booking-information-disclosure-via-account-enumeration
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00658
epssPercentile: 0.49365
ingestedAt: '2026-08-22T13:32:35.363Z'
---

## Overview

Joomla com_booking component 2.4.9 contains an information disclosure vulnerability that allows unauthenticated attackers to enumerate user accounts by exploiting the getUserData function in the customer controller. Attackers can send GET requests to index.php with option=com_booking, controller=customer, task=getUserData, and an id parameter to retrieve user names, usernames, and email addresses through brute force enumeration.

## Affected

- `book_it! = 2.4.9`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
