Impact
The Tassos Framework plugin processes certain AJAX requests through Joomla’s com_ajax entry point without adequate access checks. When an attacker sends a specifically crafted request, internal framework functions can be invoked without authentication. This flaw allows the injection of arbitrary SQL commands and the reading of files that should be protected, giving an attacker direct access to database contents and sensitive configuration files, thereby compromising both confidentiality and integrity.
Affected Systems
Product families that use the Tassos Framework plugin include Advanced Custom Fields, Convert Forms, EngageBox, Google Structured Data, and Smile Pack. No specific version information is disclosed in the CVE entry, so any release of these extensions that includes the vulnerable plugin could be affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.5, indicating critical severity. The EPSS score is reported as 2%, which is relatively low but non‑zero, suggesting a modest probability of exploitation in the wild. The flaw is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is remote unauthenticated via crafted AJAX requests to the com_ajax endpoint, exploiting an access‑control weakness (CWE‑284). No local privileges or other prerequisites are required for the attacker to achieve the full impact.
OpenCVE Enrichment