Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Joomla com_booking 2.4.9 Information Disclosure via Account Enumeration
Vulnerability Description
Joomla com_booking component 2.4.9 contains an information disclosure vulnerability that allows unauthenticated attackers to enumerate user accounts by exploiting the getUserData function in the customer controller. Attackers can send GET requests to index.php with option=com_booking, controller=customer, task=getUserData, and an id parameter to retrieve user names, usernames, and email addresses through brute force enumeration.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
通过差异性导致的信息暴露
Vulnerability Title
ARTIO Book it 侧信道信息泄露漏洞
Vulnerability Description
artio Book it是artio公司的一款适用于运动健身、 wellness、住宿、租车等多种服务行业的在线预约管理系统。 ARTIO Book it 2.4.9版本存在侧信道信息泄露漏洞,该漏洞源于customer控制器中的getUserData函数存在信息泄露问题,未经身份验证的攻击者可通过向index.php发送GET请求,利用option=com_booking、controller=customer、task=getUserData和id参数,通过暴力枚举检索用户名和电子邮件地址。
CVSS Information
N/A
Vulnerability Type
N/A