Impact
The Fabrik extension for Joomla contains an unauthenticated endpoint, list.doempty, that lacks any access‑control checks. An attacker can issue a plain HTTP GET request to this endpoint, which triggers the emptying of the target list’s database table. The result is irreversible data loss for the affected list and potential interruption of services that rely on that data. This flaw is a classic Broken Access Control vulnerability (CWE‑284).
Affected Systems
Any site running the Fabrik extension for Joomla with a version prior to 4.7.2 is affected. No specific sub‑versions were enumerated, but all releases below 4.7.2 should be considered vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.7, indicating high severity. The EPSS score is not available, and the vulnerability is not currently listed in CISA’s KEV catalog. The attacker’s path requires only unauthenticated HTTP access to the targeted site, making exploitation trivial for anyone with network visibility to the Joomla installation. Once triggered, the data is permanently lost, and no user‑level authentication is needed to perform the attack.
OpenCVE Enrichment