Impact
The Joomla! CMS vulnerability allows attackers to create custom fields through the com_fields webservice endpoints without the appropriate access controls. This flaw, identified as CWE‑284, permits an attacker to modify the site’s data layouts by adding new fields can grant the attacker elevated capabilities within the CMS, potentially affecting the integrity and availability of site data.
Affected Systems
This vulnerability affects Joomla! CMS installations that expose the com_fields webservice endpoints; no version exclusions are listed, meaning any Joomla! release lacking the patch is vulnerable.
Risk and Exploitability
The CVSS score of 6.4 denotes moderate severity. The EPSS score of <1% suggests a low probability of exploitation. Based on the description, it is inferred that the webservice endpoints do not perform additional authentication or role verification, allowing an attacker to create fields via standard HTTP requests. The vulnerability is not listed in the CISA KEV catalog, indicating that no widespread exploitation has been documented yet, but awareness and monitoring are prudent.
OpenCVE Enrichment