Impact
The vulnerability in the miniOrange OAuth Client extension for Joomla enables an attacker to modify a cookie value to authenticate as any user account, including administrators. This flaw permits arbitrary account takeover by bypassing the normal authentication checks, giving the attacker the privileges of the account they impersonate.
Affected Systems
Affected vendors and products include the miniOrange.com extensions: miniOrange OAuth Client for Joomla (vulnerable versions less than 3.2.0), OAuth Single Sign-On – OIDC SSO for Joomla (vulnerable versions less than 1.2.2), Login with Keycloak OAuth Single Sign-On (SSO) for Joomla (vulnerable versions less than 1.2.2), and Single Sign-On for Educational Institutes for Joomla (vulnerable versions less than 1.2.2). Users running Joomla with any of these unpatched extensions must consider the risk.
Risk and Exploitability
The vulnerability has a CVSS score of 10, indicating a critical level of risk. The EPSS score is less than 1%, reflecting a very low but nonzero exploitation probability, and the issue is not listed in the CISA KEV catalog at present. Attackers can exploit the flaw remotely by forging an HTTP cookie in a browser or via an HTTP request, with no additional prerequisites beyond the ability to send a crafted cookie. Because the flaw lies in cookie handling that bypasses authentication, a mitigation strategy centered on updating the extension is strongly recommended.
OpenCVE Enrichment