Impact
An unauthenticated attacker can trigger arbitrary code execution through the Fabrik front‑end listfilter model in Joomla. The flaw allows the execution of injected code with the privileges of the web server, constituting a full remote code execution vulnerability classified under CWE‑94. The high CVSS score of 10 reflects the potential for complete compromise of the affected host.
Affected Systems
The vulnerability exists in the Fabrik Joomla extension released by fabrikar.com, affecting all installations with a version earlier than 4.6.8. No other products or versions are noted as impacted.
Risk and Exploitability
With no user authentication required, the exploitation path is straightforward: an attacker sends a crafted request to a publicly reachable listfilter endpoint. The EPSS metric is not available, but the CVSS score of 10 indicates a critical attack surface. It is not listed in the CISA KEV catalog currently, yet organizations using an old Fabrik version face an imminent threat from any actor capable of sending HTTP requests to the site.
OpenCVE Enrichment