Joomla Extension - icagenda.com - ACL bypass allowing...
Moderate severity
Unreviewed
Published
Aug 14, 2026
to the GitHub Advisory Database
•
Updated Aug 14, 2026
Description
Published by the National Vulnerability Database
Aug 14, 2026
Published to the GitHub Advisory Database
Aug 14, 2026
Last updated
Aug 14, 2026
Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 - A backend operator granted access scoped to
com_icagendaonly could enumerate Joomla user profiles.References