Impact
The vulnerability resides in several Regular Labs extensions for Joomla, where AJAX endpoints fail to consistently validate CSRF tokens, component/item permissions, and trusted server‑generated form configuration. As a result, authenticated users with lower privileges can invoke lookups or modifications that exceed their authorized scope, or attackers can craft CSRF requests to perform these actions. The weakness allows an attacker to execute unauthorized operations and potentially access or alter sensitive data beyond the intended user permissions.
Affected Systems
Affected products include Advanced Module Manager, Articles Anywhere, Articles Field, Better Frontend Link, CDN, Cache Cleaner, Conditional Content, Content Templater, DB Replacer, Email Protector, GeoIP, IP Login, Keyboard Shortcuts, Modals, Modules Anywhere, Quick Index, ReReplacer, Regular Labs Extension Manager, Snippets, Sourcerer, Tooltips, Users Anywhere, and the “What? Nothing!” extension for Joomla. All installations running any of these extensions in any version are potentially impacted, as no specific version constraints are listed.
Risk and Exploitability
The CVSS score of 8 denotes high severity, indicating significant potential for compromise. The low EPSS score of < 1% indicates a very low probability of exploitation in the wild, but the presence of privilege escalation and CSRF attack paths remains a serious concern. The weakness is classified as CWE-284 and CWE-352, indicating improper access control and cross‑site request forgery. No KEV listing is available; however, organizations using these extensions should treat this as a critical issue and apply remediation promptly. Likely attack vectors involve authenticated users with low privileges or crafted cross‑site requests to the vulnerable AJAX endpoints.
OpenCVE Enrichment