Impact
The vulnerability resides in the Zoo extension for Joomla (yootheme.com) versions earlier than 4.1.66. Missing CSRF tokens on front‑end state‑changing requests allow an attacker to trigger actions such as publishing or deleting content by submitting crafted requests from a browser. Classified as CWE‑352, the flaw permits unauthorized modification of content integrity without requiring elevated privileges.
Affected Systems
The affected product is yootheme.com Zoo extension for Joomla. Only versions prior to 4.1.66 are affected; no other products or versions are listed.
Risk and Exploitability
The CVSS score of 4.6 indicates moderate severity. No EPSS score is available, so exploitation likelihood is unclear. The vulnerability is not listed in CISA’s KEV catalog, implying no confirmed large‑scale attacks. The attack vector is client‑side web application; an attacker can perform the exploit by sending a crafted HTTP request from a browser to a front‑end endpoint that changes state.
OpenCVE Enrichment