Impact
An unauthenticated guest can invoke the TF Content extension’s records.custom_action endpoint by supplying the numeric ID of a published task, causing the component to immediately dispatch its configured executor. This allows an attacker to trigger any task configured by the site administrator without authentication, potentially executing arbitrary actions defined in that task.
Affected Systems
The vulnerability affects joomlafry.com’s TF Content for Joomla extensions, specifically the 2.9.0 through 2.9.4 releases.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack paths require no authentication or special permissions beyond supplying a numeric ID, which is inferred from the description to be trivial to launch from a web browser. Consequently, the likelihood of exploitation is high for any publicly accessible site that remains unpatched.
OpenCVE Enrichment