Impact
This vulnerability is a server-side request forgery that allows an attacker to craft custom query URLs in the Cache Cleaner Pro extension for Joomla. By causing the extension to send HTTP requests to arbitrary internal or reserved network services, the flaw could expose sensitive information or allow the attacker to perform operations against internal services. The weakness is identified as CWE-918, indicating an ability to force the application to access internal resources that should be hidden from the attacker.
Affected Systems
The affected product is the Cache Cleaner Pro extension for Joomla, distributed by regularlabs.com. No specific version information is supplied in the data; users should verify the installed extension version against the vendor’s release notes.
Risk and Exploitability
The CVSS score of 9.8 marks this flaw as critical, with high potential impact on confidentiality and integrity. The EPSS score of < 1 % suggests a low current probability of exploitation, but the vulnerability remains dangerous once discovered. It is not listed in the CISA KEV catalog. The likely attack vector is through the extension’s query URL functionality, which can be invoked by any user who can interact with the extension’s interface. Although exploitation prerequisites are not detailed, the flaw can be triggered without authentication in many typical Joomla deployments, making the risk significant.
OpenCVE Enrichment