Impact
The vulnerability arises from an unescaped numeric filter in the iCagenda extension for Joomla, allowing users with backend operator permissions to inject arbitrary SQL commands. An attacker who can authenticate to the site and possesses iCagenda access can execute SQL statements that may read, modify, or delete data in the Joomla database, potentially leading to data exposure, integrity compromise, or full site takeover. The weakness is a classic SQL injection flaw (CWE-89).
Affected Systems
iCagenda.com’s iCagenda extension for Joomla is affected when its version is below 2.0.0-4.0.11. Any Joomla installation using those legacy iCagenda releases is vulnerable; newer versions are not known to be affected.
Risk and Exploitability
The CVSS score of 8.6 classifies the issue as high severity, and the exploitation requires authenticated access to the Joomla backend with iCagenda permissions. Because no EPSS score is available, the probability of exploitation is undetermined, but the lack of KEV listing does not mitigate the risk. An attacker who gains the necessary frontend or backend access can directly invoke the vulnerable numeric filter, making this a relatively straightforward attack vector for users with sufficient Joomla privileges.
OpenCVE Enrichment