Impact
The vulnerability permits an attacker to trigger state‑changing frontend operations in the iCagenda extension without a CSRF token. Because the extension does not perform the required token check, a malicious request can be crafted to register users or alter configuration settings that a normal visitor could initiate. The impact manifests as unauthorized administrative activity, potentially compromising the integrity of the website’s data.
Affected Systems
The affected product is the iCagenda extension for Joomla provided by icagenda.com. Versions prior to 2.0.0‑4.0.11 are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the extension is not listed in CISA’s KEV catalog. The EPSS score is currently unavailable. The likely attack vector requires a victim to visit or interact with a malicious page that submits a forged request to the frontend registration endpoint. Successful exploitation would allow the attacker to perform actions with the victim’s privileges, thereby compromising data integrity and potentially enabling further attacks if additional sensitive operations are exposed via the same endpoint.
OpenCVE Enrichment