Impact
The Fabrik extension for Joomla version prior to 4.7.2 contains an unauthenticated data disclosure flaw in the ajax_tables method of its elements model. An attacker can invoke this publicly accessible AJAX endpoint and retrieve a list of all database tables along with their prefixes. This exposure allows enumeration of all tables that might contain user accounts, configuration settings, and other sensitive site data, thereby compromising confidentiality.
Affected Systems
Joomla sites that host the Fabrikar.com Fabrik extension at any version lower than 4.7.2 are impacted. No other vendors or product versions are identified in the CVE data.
Risk and Exploitability
With a CVSS score of 8.7 the vulnerability is rated high severity. The exploitation requires no login and is triggered through a standard web request to the ajax_tables interface, so the likelihood of a real-world attack is significant. The EPSS score is not provided and the vulnerability is not listed in the CISA KEV catalog, but the absence of those factors does not mitigate the inherent risk presented by the unauthenticated access to database metadata.
OpenCVE Enrichment