Impact
User tags, filters and conditions in Regular Labs' Articles Anywhere and Users Anywhere Joomla extensions can be abused to retrieve user fields that are not properly restricted. The vulnerability allows an attacker to craft content that exposes authentication‑related data, raw user parameters, or restricted contact details, leading to leakage of confidential information. This weakness is a classic example of improper authorization enforcement, classified as CWE‑284.
Affected Systems
All Joomla installations that use the Articles Anywhere or Users Anywhere extensions from Regular Labs are potentially impacted. Because specific affected versions are not listed, any instance of these extensions without an updated access‑control fix should be considered vulnerable.
Risk and Exploitability
The EPSS score is below 1 %, indicating very low exploit probability, and the vulnerability is not listed in CISA KEV. The CVSS score of 6.5 indicates moderate severity. However, the potential impact of disclosing authentication and contact information is high, which raises the overall risk assessment. The likely attack vector involves any user who can input custom tags or filter expressions through the front‑end or an extension configuration page, and the exploit can be performed without elevated privileges on the site.
OpenCVE Enrichment