Impact
The conditions administration interface of several Regular Labs Joomla extensions failed to consistently enforce CSRF token verification and appropriate component or mapped‑item permission checks. This flaw can allow an attacker who submits a crafted request to alter configuration settings, insert malicious content, or otherwise elevate privileges, combining improper access control (CWE‑284) with inadequate CSRF protection (CWE‑352).
Affected Systems
Regular Labs Advanced Module Manager for Joomla, Regular Labs Conditional Content for Joomla, Regular Labs Content Templater Pro for Joomla, Regular Labs ReReplacer Pro for Joomla. No specific version information is provided for the affected products.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability, while the EPSS score of < 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The lack of CSRF token checks combined with insufficient permission enforcement means an attacker who can induce an administrator to submit a crafted request may gain elevated privileges. Based on the description, the likely attack vector is a web‑based request to the admin interface, subject to the attacker’s ability to reach the site’s backend and convince a logged‑in administrator to submit the request.
OpenCVE Enrichment