Impact
The vulnerability stems from a missing enforcement of item- and menu-level edit permissions on the save-megamenu-settings AJAX endpoint. An authenticated Joomla user can submit altered layout parameters for any menu item, effectively bypassing the intended access controls. This allows an attacker to reconfigure the site’s navigation, potentially deface content or impose unauthorized redirects. The weakness is an Access Control flaw mapped to CWE-284.
Affected Systems
The issue affects the Helix Ultimate extension for Joomla produced by joomshaper.com, specifically all releases prior to version 2.2.10.
Risk and Exploitability
The CVSS score of 5.1 indicates a medium severity. No EPSS score is available, so the likelihood of exploitation is uncertain, but the attack requires only a valid authenticated session within the Joomla backend. The vulnerability is not listed in the CISA KEV catalog, suggesting no known large-scale exploit activity. With authenticated access and no additional safeguards, an attacker can modify menu settings promptly, making the risk significant for sites that rely on the default permission settings.
OpenCVE Enrichment