Description
Joomla Extension - joomlafry.com - Unauthenticated cross-record publication and mass assignment in TF Content 2.9.0 - 2.9.4 - The extension unconditionally authorizes both creation and editing in its public `RecordController`. Its shared frontend save controller accepts the raw `jform` array, assigns the request-selected existing record ID, and saves it without filtering submitted properties through the configured form. A Guest can obtain a valid token from Joomla's public login form and modify any TF Content row, including mass-assigning `published`, `access`, and `created_by`.
Published: 2026-10-05
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Unauthenticated modification and publication of content via mass assignment
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the public RecordController of the TF Content extension where the supplied jform array is accepted without filtering, allowing creation and editing of any record. Because the controller accepts an arbitrary record ID and saves it, a guest can craft a request that changes the status, access level, or ownership of any content row. This mass assignment effectively lets an unauthenticated user cause arbitrary content to be published, hidden, or attributed to any user.

Affected Systems

Joomla installations running the TF Content extension from joomlafry.com, versions 2.9.0 through 2.9.4, are affected.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity. The exploit requires only a standard guest login to obtain a Joomla session token, enabling a crafted request that changes the status, access level, or owner of any record. While EPSS data is unavailable, the lack of formal parameter validation in the front‑end controller allows attackers to trigger the vulnerability without special conditions. The vulnerability is not listed in CISA KEV, but it poses significant damage potential due to unauthorized content manipulation.

Generated by OpenCVE AI on October 5, 2026 at 17:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the TF Content extension to the latest version that eliminates the unchecked mass assignment in the RecordController.
  • If no patch is available, restrict front‑end access to the extension’s controllers by removing Create/Edit permissions from the Public group and granting them only to Administrators and authorized editors.
  • Monitor content publication changes through Joomla’s audit log or an external monitoring system and trigger alerts when unexpected status or ownership changes occur.

Generated by OpenCVE AI on October 5, 2026 at 17:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 05 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 16:15:00 +0000

Type Values Removed Values Added
Description Joomla Extension - joomlafry.com - Unauthenticated cross-record publication and mass assignment in TF Content 2.9.0 - 2.9.4 - The extension unconditionally authorizes both creation and editing in its public `RecordController`. Its shared frontend save controller accepts the raw `jform` array, assigns the request-selected existing record ID, and saves it without filtering submitted properties through the configured form. A Guest can obtain a valid token from Joomla's public login form and modify any TF Content row, including mass-assigning `published`, `access`, and `created_by`.
Title Joomla Extension - joomlafry.com - Unauthenticated cross-record publication and mass assignment in TF Content 2.9.0 - 2.9.4
Weaknesses CWE-862
CWE-915
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-10-05T16:28:48.333Z

Reserved: 2026-09-29T16:46:15.044Z

Link: CVE-2026-102780

cve-icon Vulnrichment

Updated: 2026-10-05T16:28:43.784Z

cve-icon NVD

Status : Received

Published: 2026-10-05T16:17:04.730

Modified: 2026-10-05T17:17:10.190

Link: CVE-2026-102780

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T17:30:11Z

Weaknesses
  • CWE-862

    Missing Authorization

  • CWE-915

    Improperly Controlled Modification of Dynamically-Determined Object Attributes