Impact
A flaw in the Fabrik extension for Joomla in versions earlier than 4.7.2 allows an attacker to craft a malicious string that exploits a heredoc terminator breakout in its calc element, enabling execution of arbitrary PHP code and resulting in full remote code execution. The vulnerability is further aggravated because the onUpdateComment endpoint does not perform any access checks, meaning an unauthenticated or low‑privileged user can trigger the flaw.
Affected Systems
The affected component is the Fabrik extension for Joomla, with all releases prior to version 4.7.2 exposed to the vulnerability. Deployments that run the extension on any Joomla site, regardless of installed user roles, must confirm the version in use and update accordingly.
Risk and Exploitability
The CVSS score of 9.5 indicates a critical rating. Although an EPSS score is not available, the absence of a KEV listing does not diminish the potential for widespread exploitation, especially given the lack of access controls. Attackers can leverage the unauthenticated onUpdateComment endpoint to trigger the RCE, making this risk high in both severity and likelihood for exposed Joomla sites.
OpenCVE Enrichment