Impact
A path traversal vulnerability has been identified in the GeoIP extension for Joomla distributed by regularlabs.com. The extension’s update process extracts ZIP archives containing the GeoIP database without validating file paths. An attacker who can supply a crafted archive during a database update can cause files to be written outside the intended directory, potentially allowing overwrite of existing files or creation of new files in arbitrary locations. If such files reside in a web‑executable location, this could enable execution of malicious code on the Joomla site.
Affected Systems
The flaw affects the GeoIP extension for Joomla produced by regularlabs.com. No specific version range is supplied in the CVE data, so administrators should verify the installed version against the vendor’s release notes to determine whether it is impacted.
Risk and Exploitability
The CVSS score of 9.8 signals a critical vulnerability. The EPSS score of less than 1% indicates a very low likelihood of exploitation at this time, and the flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves manipulating the extension’s update mechanism, such as by tampering with the update feed or delivering a malicious archive to the update system. Successful exploitation could lead to arbitrary file creation or overwrite, with potential impact on confidentiality, integrity, or availability of the Joomla installation.
OpenCVE Enrichment