Impact
An improper access control check in Joomla! allows users or attackers to retrieve contact information for items that are not normally accessible. Because contact data is injected into public schema.org snippets, the flaw can expose private or restricted contact details, potentially revealing sensitive organizational information. This weakness falls under the category of improper authorization, as the system fails to enforce the intended permissions for viewable contacts.
Affected Systems
This issue affects Joomla! CMS versions 5.1.0 through 5.4.7 and 6.0.0 through 6.1.2.
Risk and Exploitability
The vulnerability has a CVSS score of 5.1, indicating a moderate level of severity. EPSS is not available and the flaw is not listed in the CISA KEV catalog. Attackers can exploit the flaw by accessing the affected site as a guest or through a crafted request to the contact list endpoint, without any special privileges. The risk is moderate in environments where unsolicited contact data could be valuable to attackers.
OpenCVE Enrichment