Impact
The Convert Forms extension’s front‑end submissions page failed to enforce access control, enabling any visitor to list a form’s submissions. This client‑controlled validation bypass allows unauthenticated users to view or download content that may be intended for private use, violating confidentiality and potentially exposing sensitive data.
Affected Systems
The flaw affects the Convert Forms extension for Joomla provided by tassos.gr. Versions prior to 5.2.5 expose the submissions view to all visitors without authentication checks.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. An attacker needs only to visit the public submissions page, a trivial action that requires no special privileges or credentials. Given the ease of exploitation and the potential for data exposure, the risk of abuse is significant.
OpenCVE Enrichment