Impact
A forged clfgd field in the Aimy Captcha-Less Form Guard extension allows an attacker to inject a PHP object that is deserialized by the application, which satisfies CWE-502. The vulnerability provides a direct path to execute arbitrary PHP code on the Joomla site, giving an attacker full control over the server and, depending on the Joomla configuration, the ability to tamper with site data, install backdoors, or further compromise the environment.
Affected Systems
Aim Extensions operates the Aimy Captcha-Less Form Guard plugin for Joomla. Versions 18.0 through 20.0 are affected and expose the deserialization flaw. Joomla sites that have installed any of these versions are susceptible.
Risk and Exploitability
The CVSS score of 10 reflects the high impact of remote code execution. EPSS indicates a low probability of exploitation at present, with the score shown as <1%. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, requiring the submission of a crafted HTTP request containing a bogus clfgd field; no additional authentication or privilege escalation steps are described, so the flaw can be used from an unauthenticated client that can access the form. Given the severity, even low exploitation probability warrants rapid action.
OpenCVE Enrichment