Impact
A flaw in the comment controller of the Zoo extension for Joomla allows anyone without authentication to modify tags associated with content. The missing access‑control checks let an attacker change tag data, potentially altering how items are classified or displayed and enabling defacement or content manipulation. This weakness is rooted in improper access control (CWE‑284) and cross‑site request forgery issues (CWE‑352).
Affected Systems
Joomla extension "Zoo" developed by yootheme.com. All versions below 4.1.65 are affected; the vulnerability exists in every release that predates 4.1.65 and can be encountered when the extension is installed in a Joomla site using any supported Joomla version.
Risk and Exploitability
The CVSS score of 6.9 classifies the issue as moderate severity, while the EPSS score of less than 1% indicates a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Because the endpoint is accessible to unauthenticated users and does not require any credentials, the likely attack vector is a simple HTTP request to the comment controller, potentially automated or used in conjunction with other site weaknesses. Exploitation requires no special conditions beyond reaching the vulnerable resource.
OpenCVE Enrichment