Impact
The Cache Cleaner Pro extension for Joomla stores CDN credentials in the query string of administrator request URLs. This results in a direct information disclosure that allows an unauthorized party to obtain credentials that provide control over the CDN service. Because the flaw is marked as CWE-200 (Information Exposure), the exposed data is highly valuable and can be used to compromise content delivery, potentially to modify cached content or serve as a foothold for further attacks. The CVE description does not indicate limited scope, implying that any installation of the extension that has not received a patch may be vulnerable.
Affected Systems
The Cache Cleaner Pro extension developed by regularlabs.com for Joomla is the affected component. The public CVE entry does not list specific version numbers; therefore, any user of the extension that has not applied the latest update is potentially at risk.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, while the EPSS score of < 1% suggests a low probability of exploitation at the moment and it is not catalogued in CISA KEV. Based on the description, it is inferred that the likely attack vector is an attacker who can read request logs or intercept traffic, for example via compromised network devices or temporary access to the site's logging infrastructure. The vulnerability does not require higher‑level Joomla privileges; read access to logs or traffic is sufficient. The high CVSS reflects that successful exploitation would grant the attacker full control of the CDN service, potentially leading to significant availability or confidentiality impacts.
OpenCVE Enrichment