Impact
The vulnerability, classified as a Server‑Side Request Forgery (CWE‑918), arises from the Articles Anywhere and Users Anywhere Joomla extensions accepting content‑controlled image URLs without verifying that the retrieved content is a safe image or that the destination falls within a permitted host range. An attacker can craft a URL that causes the extension to request resources from private or reserved network services, follow unsafe redirects, and store the returned data in a publicly writable folder. This enables SSRF, internal data exposure, and arbitrary file write that can be served by the web server.
Affected Systems
The affected products are the Articles Anywhere Pro extension and the Users Anywhere Pro extension for Joomla, developed by regularlabs.com. No specific version ranges are reported, so any installation that uses these extensions may be vulnerable until the vendor releases a fix.
Risk and Exploitability
The EPSS score is below one percent and the issue is not listed in the CISA KEV catalog, which suggests a low probability of immediate exploitation. The CVSS score of 7.5 indicates high severity, while the impact of a successful exploit is high because it can lead to disclosure of internal data or execution of arbitrary web‑accessible content. The risk remains significant if the extensions are exposed to untrusted input. The likely attack vector is a web request using a crafted image URL supplied by an attacker through article or user content editing interfaces.
OpenCVE Enrichment