# CVE-2023-54357

## Summary

- **CVE ID:** CVE-2023-54357
- **Severity:** HIGH
- **CVSS Score:** 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-203
- **Published:** Jun 19, 2026
- **Last Modified:** Jun 23, 2026

## Description

Joomla com_booking component 2.4.9 contains an information disclosure vulnerability that allows unauthenticated attackers to enumerate user accounts by exploiting the getUserData function in the customer controller. Attackers can send GET requests to index.php with option=com_booking, controller=customer, task=getUserData, and an id parameter to retrieve user names, usernames, and email addresses through brute force enumeration.

## Affected Products

- Artio — Joomla! com_booking component (2.4.9)

## References

- [CNA](https://www.exploit-db.com/exploits/51595)
- [CNA](http://www.artio.net/)
- [CNA](http://www.artio.net/downloads/joomla/book-it/book-it-2-free/download)
- [CNA](https://www.vulncheck.com/advisories/joomla-com-booking-information-disclosure-via-account-enumeration)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.49%
- **EPSS Percentile:** 40.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._