Impact
The Fabrik extension for Joomla contains an unsanitized PHP form element that permits arbitrary code injection and results in unauthenticated remote code execution in all versions lower than 4.7.2. An attacker can supply malicious input that is executed on the server, giving full control over the affected system. The vulnerability is a classic Code Injection flaw (CWE‑94) and enables remote command execution without authentication.
Affected Systems
The flaw affects all installations of the Fabrik extension for Joomla with versions lower than 4.7.2. The vulnerability is tied to fabrikar.com’s Fabrik component, and no specific minor version ranges are listed beyond the <4.7.2 cutoff.
Risk and Exploitability
With a CVSS score of 10.0, this issue is categorized as critical. The EPSS score is not available, but the lack of a published exploit in KEV and the unauthenticated nature of the attack vector suggest that automated exploitation is feasible and likely to be attempted. Attackers can exploit the flaw by sending specially crafted form data; no special privileges or preconditions are required beyond network access to the vulnerable Joomla site.
OpenCVE Enrichment