Impact
Based on the description, it is inferred that the vulnerability allows an attacker to inject or forge client‑IP headers that the GeoIP extension trusts, enabling spoofing of the originating IP address. Because the extension uses these forwarded headers for GeoIP lookups and subsequent access‑control decisions, a spoofed IP can bypass geo‑blocking rules or other geolocation‑based restrictions. This grants an attacker the ability to compromise the integrity of location‑based checks and potentially gain access to restricted content or services. The weakness is identified as Authentication Spoofing (CWE‑290).
Affected Systems
The affected product is the GeoIP extension for Joomla maintained by regularlabs.com. No specific version range is provided in the current data; administrators should review installed extension versions against the vendor’s release notes for known fixes.
Risk and Exploitability
The EPSS score of less than 1 % indicates a very low probability of exploitation at the time of this analysis. The CVSS score of 6.5 reflects a medium severity vulnerability. Although not listed in the CISA KEV catalog, the ability to spoof client‑IP headers and bypass geo‑blocking rules can have significant operational effects. Based on the description, the likely attack vector is inferred to involve the attacker crafting custom forwarded‑IP headers to a server running the vulnerable GeoIP extension, typically achieved by controlling HTTP requests to the Joomla site.
OpenCVE Enrichment