Impact
The vulnerability is an unauthenticated SQL injection in the iCagenda extension for Joomla, allowing an attacker to execute arbitrary SQL commands via the com_ajax endpoint without a session, token, or account. This flaw, identified as CWE‑89, can lead to unauthorized read, modification, or deletion of database contents, potentially giving attackers full access to sensitive data or enabling further attacks that compromise the affected system.
Affected Systems
The issue affects the iCagenda extension for Joomla distributed by icagenda.com. All installations using version 4.0.0 through 4.0.11 are vulnerable; versions prior to 4.0.0 and 4.0.12 and later contain the fix.
Risk and Exploitability
The CVSS score of 9.2 marks this flaw as critical, and although EPSS data is not available, the lack of the need for authentication makes exploitation highly feasible from any internet‑connected Joomla site hosting the vulnerable component. The vulnerability is not listed in the CISA KEV catalog, but the high severity and wide attack surface call for urgent remediation.
OpenCVE Enrichment