Impact
The Modules Anywhere extension for Joomla contains inconsistent checks for CSRF tokens and user privileges. When an authenticated Joomla user opens the editor popup, the system may return restricted module data even if the user lacks permission or a valid request token. This flaw does not allow code execution but can expose sensitive configuration or content that should be protected by module permissions.
Affected Systems
The vulnerability affects the Modules Anywhere extension published by RegularLabs for the Joomla content management system. No specific version range is listed, so all current or unpatched installations are potentially impacted until a fix is applied.
Risk and Exploitability
The flaw carries a CVSS score of 8.1, indicating high risk, yet the EPSS score is less than 1%, suggesting a low probability of exploitation in the wild. The issue is not listed in CISA’s KEV catalog. An attacker would need an authenticated Joomla account and access to the editor popup; the attack would be limited to data exposure and privilege escalation within the module context, without remote code execution.
OpenCVE Enrichment