Impact
An improper access check in Joomla! CMS’s com_workflow component enables an attacker to retrieve workflow stage and transition data without proper authorization. The flaw is a classic access‑control weakness (CWE‑284) that exposes the confidentiality of workflow structures and processes.
Affected Systems
The Joomla! CMS product is impacted. No specific patched version is listed, indicating that the issue may exist across multiple releases until an official fix is applied or that the component is disabled.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. The EPSS score of less than 1% suggests a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a web‑based request to the com_workflow endpoint, where the attacker can uncover workflow configuration information but does not gain code execution or broader system compromise.
OpenCVE Enrichment