Impact
The vulnerability is an improper access control in Joomla! core that allows an unauthorized user to create categories through the webservice endpoints. This flaw could let an attacker add categories they should not have permission to create, potentially enabling further malicious activity or disrupting site organization. It is inferred that both unauthenticated and insufficiently privileged users can trigger this flaw, as the access check does not verify appropriate rights before allowing category creation.
Affected Systems
Joomla! CMS, released under the Joomla! Project, is affected in all versions from 4.0.0 through 5.4.7 and from 6.0.0 through 6.1.2. Users running any of these releases should verify whether their installation falls within these version ranges.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Attackers can leverage the exposed webservice endpoints to create categories without proper authorization, typically by sending requests to the affected APIs. No authentication or elevated permissions are required beyond normal site access, making the flaw remotely exploitable for unauthorized category creation.
OpenCVE Enrichment