Impact
The vulnerability originates from inconsistent enforcement of CSRF token checks and privilege checks within the Regular Labs Extension Manager for Joomla. Administrator routes responsible for installing, updating, and uninstalling extensions fail to uniformly verify that the caller possesses component‑management permissions and do not consistently validate the CSRF token. Consequently, an attacker who gains access to the Joomla backend—either as a non‑administrator with partial privileges or by submitting a forged CSRF request—can instruct the extension manager to deploy, modify, or remove extensions. This allows malicious code injection and can lead to full control over the site’s functionality and data.
Affected Systems
The affected product is the Regular Labs Extension Manager extension for the Joomla CMS. No specific vulnerable release is identified, so all presently installed versions should be treated as vulnerable until a vendor‑supplied fix is released.
Risk and Exploitability
The CVSS score of 8.8 reflects high severity. The EPSS score of less than 1 % indicates a very low but non‑zero probability of exploitation in the current threat landscape, and the vulnerability is not listed in CISA’s KEV catalog. Successful exploitation requires backend access with at least limited administrative rights or the ability to forge a CSRF request. When exploited, the attacker can install, update, or delete extensions, potentially leading to arbitrary code execution, data exfiltration, or site disruption.
OpenCVE Enrichment