Impact
The Fabrik extension for Joomla contains an authentication bypass in the form.inlineedit controller. Because no access control check is performed, any visitor can invoke this endpoint and retrieve database rows that belong to private forms. The result is a direct compromise of confidentiality, allowing an attacker to view data that should remain restricted, although there is no evidence that execution or arbitrary code writing is possible.
Affected Systems
This flaw affects all versions of the Fabrik extension released by fabrikar.com that are older than 4.7.3. Administrators should verify the installed version of the extension and upgrade if it falls within this range.
Risk and Exploitability
With a CVSS score of 6.9 the vulnerability is considered moderate. No EPSS data is available, and the issue is not listed in the CISA KEV catalog, suggesting limited known exploitation. The likely attack vector is an unauthenticated web request to the inineedit endpoint. An attacker can pull any row from the database without needing additional privileges or authentication.
OpenCVE Enrichment