Impact
The Fabrik extension for Joomla contains an endpoint that allows any user, without authentication, to modify any comment. This leads to unauthorized data tampering, potentially altering user-generated content and undermining the integrity of the application. The weakness is an access control failure, classified as CWE‑284.
Affected Systems
The vulnerability affects the Fabrik extension for Joomla provided by fabrikar.com when deployed in any version earlier than 4.7.2. No specific sub‑versions are enumerated; any installation using a pre‑4.7.2 build is potentially impacted.
Risk and Exploitability
The flaw carries a CVSS score of 6.9, indicating moderate severity and an integrity impact, as the attacker can alter any comment. The EPSS score is not available, so the exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is unauthenticated misuse of the onUpdateComment endpoint, requiring no special permissions.
OpenCVE Enrichment