Impact
The vulnerability allows an attacker to insert forged client‑IP headers that the IP Login extension accepts without verifying the source proxy. Because those headers are used to determine automatic login, the attacker can cause the system to credential an account that matches the spoofed IP. This can lead to unauthorized access.
Affected Systems
The affected product is the regularlabs.com IP Login extension for Joomla. No specific versions are listed, so any installation that has not applied an official update may be vulnerable.
Risk and Exploitability
The extension relies on trust of a forwarded client‑IP header without requiring configuration of a trusted proxy, making the attack vector straightforward for anyone able to control HTTP request headers. The CVSS Score is 7.5, the EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog. However, the capacity to spoof identity and gain unauthorized account access suggests a high risk for organizations that use this extension without additional safeguards.
OpenCVE Enrichment