Impact
The vulnerability allows an unauthenticated attacker to execute arbitrary code by exploiting the ajax_calc feature of the Fabrik calc plugin. The flaw arises from improper control over user‑supplied input, enabling arbitrary code execution as described by CWE-94. An attacker who can trigger this endpoint could gain full control of the affected server’s environment, compromise data confidentiality, integrity, and availability, and potentially pivot to other systems.
Affected Systems
The Fabrik extension for Joomla versions earlier than 4.6.7 is affected. This includes all installations that rely on the ajax_calc functionality of the Fabrik plugin without a later patch. If an organization uses older versions of the extension, the vulnerability applies regardless of other Joomla component versions.
Risk and Exploitability
The CVSS score of 10 indicates the highest severity, and no exploit probability data is available. The vulnerability is not listed in the CISA KEV catalog, but the lack of an authentication requirement and the generic nature of the ajax_calc endpoint make successful exploitation highly feasible in real‑world scenarios. The likely attack vector is web‑based, requiring only an unauthenticated HTTP request to the Fabrik ajax_calc endpoint.
OpenCVE Enrichment