Impact
The T4 Page Builder extension for Joomla includes a public AJAX endpoint that accepts contact requests without authentication. An attacker can submit arbitrary recipients, subject lines, and HTML bodies, causing the site to send mail to any external address from its configured sender identity. This permits the extension to function as an open mail relay, enabling spam and phishing campaigns that compromise the site's reputation and potentially lead to blacklisting.
Affected Systems
Vendors: joomlart.com; Product: T4 Page Builder extension for Joomla. Versions below 2.3.0 are affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.9, indicating moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the contact endpoint requires no authentication or CSRF protection and lacks rate limiting, any web user can trigger it, making exploitation straightforward. The lack of authentication and protection means an attacker can generate large volumes of outgoing mail, causing spam or phishing abuse, damaging the site's reputation and subjecting its mail server to potential blocklisting.
OpenCVE Enrichment