Impact
The vulnerability lies within Regular Labs Joomla extensions where the Conditions editor builds a default Condition Set name from the linked item. The code accepts database table and column names directly from the request. Although the names are quoted as SQL identifiers, no restrictions enforce that they belong to the tables and columns used by the supported integrations. Consequently, an attacker can supply a valid but unrelated database field name. This bypasses authorization checks, allowing the attacker to retrieve data from tables not intended to sensitive database information and is classified as an information‑disclosure weakness (CWE‑200).
Affected Systems
The problem affects Regular Labs' Joomla extensions released before the following versions: Advanced Module Manager (Free and Pro) older than 12.1.0; Conditional Content (Free and Pro) older than 8.0.0; Content Templater (Pro) older than 14.2.0; ReReplacer (Pro) older than 16.2.0. Any site running these extensions with the outdated versions is vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates high severity. Because the flaw enables external attackers to supply arbitrary table and column names via a web request, it is exploitable over the network without authentication, provided the site allows typical Joomla administrative or user‑level interactions. The EPSS score is <1% (approximately 0.22%) and the vulnerability is not listed in CISA's KEV catalog, suggesting no known attacks yet. However, the ease of manipulating a query and the potential for sensitive data exposure make this a significant risk or further compromise.
OpenCVE Enrichment