Impact
A missing authentication check in the Joomla extensions from miniorgange.com allows an unauthenticated actor to delete any installed extension from the site. This flaw is an access control deficiency (CWE-284) that can disable critical functionality or remove security components, potentially leading to site disruption or facilitating further compromise.
Affected Systems
The vulnerability impacts only free versions of the miniOrange extensions for Joomla. The affected plugins include Custom API for Joomla, Import Export Users for Joomla, JoomAI – AI Assistant for Joomla, JoomShield, Keycloak user sync, LDAP Integration with Active Directory and OpenLDAP, Login with Keycloak OAuth SSO, OAuth Server, OAuth Single Sign-On – OIDC SSO, OTP Verification, Okta User sync, Restrict Files, SAML 2.0 IDP, SAML SP Single Sign On – Login with ADFS, SAML SSO login with google Apps, SCIM User Provisioning, Single Sign On for Educational Institutes, Staff/Employee Business Directory Search, Two Factor Authentication, Web3 – Crypto wallet Login & NFT token gating, miniOrange Oauth Client, and miniOrange User Provisioning with Azure. No specific version information is supplied, but all free editions are affected.
Risk and Exploitability
With a CVSS score of 8.8, the vulnerability is classified as high severity. The EPSS score is not available and the issue is not listed in CISA KEV, indicating no confirmed exploits yet. The attack vector is likely remote and requires no authentication, allowing any unauthenticated web user with access to the Joomla administration interfaces to issue deletion requests. Because the flaw permits arbitrary extension removal, it can cause denial of service to site functionality and provide an avenue for attackers to disable or replace security extensions, elevating the potential impact.
OpenCVE Enrichment