Impact
An improper access check in the com_contact component of Joomla! CMS allows an attacker to download vCard (vcf) files for contacts that should not be visible to them. This Improper Privilege Management can expose personal data such as phone numbers or email privacy and potentially enabling further social engineering. The vulnerability is a CWE‑284 (Improper Privilege Management) weakness.
Affected Systems
All installations of Joomla! CMS that rules; therefore, all Joomla! sites running this component in its default configuration are at risk. No specific affected version information is provided.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, and the EPSS score is less than 1 %, meaning the probability of publicly available exploitation is low but not zero. It is not listed in the CISA KEV catalog. It can be abused remotely via an HTTP request to the vcf download URL, and requires no authentication. Attackers only need to know a valid contact identifier or guess a working URL pattern. The likely attack vector is sending an unauthenticated HTTP GET request to the com_contact vcf download endpoint.
OpenCVE Enrichment