Impact
The vulnerability stems from Joomla! Core’s failure to properly validate configured CORS origins in forms of HTTP requests. A malicious foreign origin can send cross‑origin requests that the server accepts, bypassing the intended same‑origin policy. This flaw, classified as CWE‑93, enables an attacker to retrieve responses from protected endpoints, potentially revealing sensitive data or session information to the attacker’s domain. The impact is limited to data disclosure rather than code execution but can still compromise confidentiality of user or administrative information.
Affected Systems
Joomla! CMS from versions 4.0.0 through 5.4.7 and 6.0.0 through 6.1.2 are affected. The Joomla! Project maintains these releases under the Joomla! CMS product line.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity, with the vulnerability likely exploitable over the network via manipulated HTTP requests. EPSS data are not available, so the current exploitation probability remains undetermined, and the vulnerability is not listed in CISA’s KEV catalog. The most probable attack vector involves an attacker hosting a malicious website which sends crafted CORS requests to the vulnerable Joomla! site, gaining unintended access to response data.
OpenCVE Enrichment