Impact
The Fabrik extension for Joomla contains a path traversal vulnerability in the handling of image elements in versions older than 4.7.2. An attacker can craft an image parameter that resolves to arbitrary filesystem paths, allowing the reading of files not intended to be publicly accessible. This can expose sensitive files, configuration data, or other information, compromising confidentiality and potentially enabling further exploitation.
Affected Systems
Fabrik extension for Joomla by fabrikar.com is affected in all releases prior to 4.7.3. Websites running these versions are vulnerable.
Risk and Exploitability
The CVSS score of 10 indicates an extremely high risk. Although the EPSS score is not available, the vulnerability is not listed in the CISA KEV catalog yet, but the severity suggests a high likelihood of exploitation, especially on sites that allow users to upload or specify image elements. The likely attack vector is through the web interface, where an attacker can embed a malicious image element in a form or content that triggers the path traversal.
OpenCVE Enrichment