Impact
The vulnerability resides in the public RecordController of the TF Content extension where the supplied jform array is accepted without filtering, allowing creation and editing of any record. Because the controller accepts an arbitrary record ID and saves it, a guest can craft a request that changes the status, access level, or ownership of any content row. This mass assignment effectively lets an unauthenticated user cause arbitrary content to be published, hidden, or attributed to any user.
Affected Systems
Joomla installations running the TF Content extension from joomlafry.com, versions 2.9.0 through 2.9.4, are affected.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. The exploit requires only a standard guest login to obtain a Joomla session token, enabling a crafted request that changes the status, access level, or owner of any record. While EPSS data is unavailable, the lack of formal parameter validation in the front‑end controller allows attackers to trigger the vulnerability without special conditions. The vulnerability is not listed in CISA KEV, but it poses significant damage potential due to unauthorized content manipulation.
OpenCVE Enrichment