Impact
The Event Gallery extension for Joomla contains a CSRF flaw that permits malicious actors to trigger various cart actions without user consent. The flaw allows an attacker to craft URLs or embed forms that, when accessed by an authenticated user, perform cart operations such as adding or removing items. This can result in unauthorized purchases, financial loss, or manipulation of cart state. The weakness is identified as CWE-352, indicating a lack of proper request validation.
Affected Systems
The vulnerability affects the svenbluege.de:Event Gallery for Joomla extension prior to version 6.5.0. No additional version details are supplied, so all installations below 6.5.0 are considered vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium to high severity. Based on the description, it is inferred that an exploit can be achieved remotely through a malicious web page or link that forces an authenticated user to carry out cart actions. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests a lower known exploitation rate but still a significant risk due to the potential impact on business operations.
OpenCVE Enrichment