Impact
The vulnerability arises from an improper access control check that permits anyone to perform batch copy operations on items they are not permitted to edit. This flaw can lead to the creation of duplicate or unauthorized content, undermining the integrity and trustworthiness of the site’s data and potentially facilitating the spread of unapproved material. The flaw is classified as a CWE‑284: Improper Control of Access Permissions.
Affected Systems
The Joomla Content Management System is affected, specifically the core releases from Joomla 4.0.0 through 5.4.7 and from 6.0.0 through 6.1.2. Users operating these versions should review whether they can access the back‑end batch copy feature.
Risk and Exploitability
The CVSS base score of 5.1 indicates a medium severity vulnerability. No EPSS score is available, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is a web‑based request to the batch copy endpoint, which could be triggered by any user with access to the administrative interface or by any authenticated user with basic permissions. While the flaw does not enable code execution or credential theft, it can compromise content integrity and may be leveraged for malicious content duplication, especially in mis‑configured environments.
OpenCVE Enrichment