Impact
The flaw resides in Regular Labs’ Articles Anywhere and Users Anywhere extensions for Joomla where query‑cache keys fail to include a bounded time component. This weakness, catalogued as CWE‑524, permits cached results to persist beyond their intended validity, allowing unauthorized users to retrieve content that has expired or is scheduled for future publication, thus leaking sensitive time‑restricted information.
Affected Systems
Regular Labs’ Articles Anywhere and Users Anywhere extensions for Joomla. The issue affects all installations that use query caching in these extensions. No specific version information is provided, so any instance running the affected extensions remains potentially vulnerable until a patch is applied.
Risk and Exploitability
The flaw carries a CVSS score of 7.5, with an EPSS less than 1% indicating a currently low exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker could exploit the lack of a bounded time component in cache keys by triggering cached queries through the Joomla web interface, thereby retrieving content that has either expired or is scheduled for future publication. The impact is limited to sensitive content exposure rather than code execution or denial of service.
OpenCVE Enrichment