Impact
The DeleteComment endpoint does not perform any access checks, allowing any user to delete any comment in Fabrik versions older than 4.7.2. This results in loss of data integrity and potential defacement or loss of user feedback. The weakness is an unauthorized deletion control flaw (CWE-284).
Affected Systems
The vulnerability affects the Fabrik extension for Joomla provided by fabrikar.com for all versions prior to 4.7.2. No specific sub‑versions are listed, so any installation using a vulnerable release is impacted.
Risk and Exploitability
With a CVSS score of 6.9 the risk is moderate. The EPSS score is not reported, and the flaw is not currently listed in CISA KEV. The endpoint is accessible without authentication, so an attacker can trigger deletion remotely by sending a request to DeleteComment. No additional conditions are specified in the report.
OpenCVE Enrichment