Impact
The vulnerability stems from inconsistent use of CSRF tokens and insufficient permission checks across several administrator actions in Regular Labs Joomla extensions, including Content Templater, ReReplacer and Snippets. This flaw allows an attacker who can forge a CSRF request or who has access to an unauthorized backend account to read, create or modify extension settings and items without proper authorization. The direct impact is the compromise of extension configuration, potentially leading to persistence of malicious settings or influencing site behavior in ways that benefit an attacker.
Affected Systems
Regular Labs products for Joomla – specifically the Content Templater, ReReplacer and Snippets extensions. No version information is provided in the advisory, so any deployment of these extensions remains potentially vulnerable until a patch is applied.
Risk and Exploitability
The EPSS score is reported as less than 1%, indicating a very low but non‑zero likelihood that this vulnerability will be exploited in the wild. The vulnerability involves only administrative functions, so it does not provide immediate remote code execution. However, an attacker who can forge a CSRF request or has access to an unauthorized backend account could read, create, or modify the configuration and items of the affected Joomla extensions, potentially allowing persistence of malicious settings or altering site behavior. Although the CVSS score is 8.8, the combination of low exploitation probability, lack of KEV listing, and the administrative scope results in a moderate to high risk for installations that expose these extensions to untrusted users or fail to enforce strict role‑based access controls. Exploitation would likely require posting a crafted CSRF request or leveraging an existing unauthorized backend account to reach the vulnerable import and export endpoints.
OpenCVE Enrichment