Impact
Administrator routes and replacement requests in the DB Replacer extension did not consistently enforce Super User or a CSRF attack to execute database replacement commands, which could corrupt data or compromise the entire site. The flaw is an instance of improper authorization (CWE-284).
Affected Systems
The vulnerability affects the DB Replacer extension for Joomla provided by regularlabs.com. No specific version information is available in the CVE data.
Risk and Exploitability
The EPSS score is <1%, indicating a very low but nonzero exploitation probability. The vulnerability is not listed in CISA’s KEV catalog, yet the impact remains high because an attacker can manipulate the database through the backend. The likely attack vector involves accessing backend routes without proper authorization or exploiting a CSRF vulnerability to submit replacement requests. Due to the lack of mitigation in the current release, the risk remains significant for any site running this extension.
OpenCVE Enrichment