Impact
The vulnerability allows an unauthenticated attacker to execute arbitrary code by exploiting the ajax_calc feature of the Fabrik calc plugin, a flaw present in Fabrik versions older than 4.7.2. It arises from improper control over user‑supplied input, enabling arbitrary code execution as described by CWE‑94. An attacker who can trigger this endpoint could gain full control of the affected server’s environment, compromise data confidentiality, integrity, and availability, and potentially pivot to other systems.
Affected Systems
The Fabrik extension for Joomla versions older than 4.7.2 is affected. This includes all installations that rely on the ajax_calc functionality of the Fabrik plugin without a later patch. If an organization uses older versions of the extension, the vulnerability applies regardless of other Joomla component versions.
Risk and Exploitability
The CVSS score of 10 indicates the highest severity, and the EPSS score < 1% indicates a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog, but the lack of an authentication requirement and the generic nature of the ajax_calc endpoint make successful exploitation highly feasible in real‑world scenarios. The likely attack vector is web‑based, requiring only an unauthenticated HTTP request to the Fabrik ajax_calc endpoint.
OpenCVE Enrichment