Joomla · Com Booking · CVE-2023-54357
**Name of the Vulnerable Software and Affected Versions**
Joomla com booking component version 2.4.9
**Description**
An information disclosure issue allows unauthenticated attackers to enumerate user accounts. By exploiting the `getUserData()` function in the customer controller, attackers can send GET requests to the 'index.php' endpoint with the parameters `option=com booking`, `controller=customer`, `task=getUserData`, and `id` to retrieve user names, usernames, and email addresses through brute force enumeration.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.