Impact
The vulnerability arises from inconsistent checks on CSRF tokens and Super User privileges in database‑update requests for the GeoIP extension. This flaw allows an attacker to perform unauthorized updates to the database, potentially altering configuration, injecting malicious data, or bypassing intended access controls. The impacted data could be used to further compromise the Joomla site or exfiltrate sensitive information.
Affected Systems
The GeoIP extension for Joomla provided by regularlabs.com is affected. No specific version information is supplied; therefore all installations of the extension are potentially vulnerable until a patch is applied.
Risk and Exploitability
The EPSS score is reported as less than 1%, and the vulnerability is not listed in CISA's KEV catalog, indicating a low probability of immediate exploitation. However, the potential impact of unauthorized database modification is high, reflected in the CVSS score of 8.8. Based on the description, it is inferred that the likely attack vector is forging HTTP requests to the update endpoints, which could be achieved by a compromised user session or via a manually crafted request from the internet, depending on the hosting environment. The attacker would need to bypass the missing token and privilege checks to gain the necessary privileges to perform the update.
OpenCVE Enrichment