Impact
The vulnerability results from inadequate validation of image elements in Fabrik versions older than 4.7.2 for Joomla, allowing attackers to embed and execute arbitrary code on the server. This code injection (CWE‑94) can lead to full compromise of the affected site, exposing confidential data, enabling defacement, or facilitating other malicious activity. The high CVSS score of 10 reflects the severity and potential impact on confidentiality, integrity, and availability.
Affected Systems
The issue affects the Fabrik extension distributed by fabrikar.com, any Joomla installation using versions of Fabrik older than 4.7.2. No specific sub‑versions were listed, so all releases prior to 4.7.2 are considered vulnerable.
Risk and Exploitability
The CVSS score of 10 indicates a critical severity. The EPSS score is unavailable, but the flaw’s critical nature suggests a high likelihood of exploitation once discovered. It is not currently listed in the CISA Known Exploited Vulnerabilities catalog (KEV). Attackers can exploit the weakness remotely by delivering a crafted image payload through a web request to the affected site, which the extension processes without adequate sanitization.
OpenCVE Enrichment