Impact
The flaw permits remote clients to forge IP and GeoIP related forwarded headers, such as X‑Forwarded‑For, that the Regular Labs conditions manager trusts when evaluating location rules. By sending crafted requests, an attacker can make the extension believe the client originates from an allowed geographic region or IP range, thereby gaining access to content or functionality that should be restricted. The weakness is an Authorization Failure reflected in CWE‑290.
Affected Systems
All versions of Regular Labs Advanced Module Manager, Conditional Content, Content Templater Pro, and ReReplacer Pro extensions for Joomla are potentially impacted, as no specific affected‑version data was provided.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity vulnerability that provides a remote, non‑privileged attacker a broad means to subvert location‑based controls. The EPSS score of less than 1% points to a very low likelihood of exploitation in the wild, yet the lack of a CISA KEV listing does not reduce the need for mitigation in environments that enforce geographic restrictions. Based on the description, it is inferred that exploitation requires only the ability to send HTTP requests with manipulated forwarded headers; no additional credentials or system access are needed.
OpenCVE Enrichment