Description
Joomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager (Free, Pro) < 12.1.0, Conditional Content (Free, Pro) < 8.0.0, Content Templater (Pro) < 14.2.0, ReReplacer (Pro) < 16.2.0 for Joomla - The Conditions editor creates a default Condition Set name from the item to which the set is linked. The affected code accepts the database table and label-column names from the request. Although these names are quoted as SQL identifiers, they are not restricted to the tables and columns used by supported Regular Labs integrations. An attacker can therefore select a valid but unrelated database field. This is an authorization failure rather than SQL injection.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability lies within Regular Labs Joomla extensions where the Conditions editor builds a default Condition Set name from the linked item. The code accepts database table and column names directly from the request. Although the names are quoted as SQL identifiers, no restrictions enforce that they belong to the tables and columns used by the supported integrations. Consequently, an attacker can supply a valid but unrelated database field name. This bypasses authorization checks, allowing the attacker to retrieve data from tables not intended to sensitive database information and is classified as an information‑disclosure weakness (CWE‑200).

Affected Systems

The problem affects Regular Labs' Joomla extensions released before the following versions: Advanced Module Manager (Free and Pro) older than 12.1.0; Conditional Content (Free and Pro) older than 8.0.0; Content Templater (Pro) older than 14.2.0; ReReplacer (Pro) older than 16.2.0. Any site running these extensions with the outdated versions is vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates high severity. Because the flaw enables external attackers to supply arbitrary table and column names via a web request, it is exploitable over the network without authentication, provided the site allows typical Joomla administrative or user‑level interactions. The EPSS score is <1% (approximately 0.22%) and the vulnerability is not listed in CISA's KEV catalog, suggesting no known attacks yet. However, the ease of manipulating a query and the potential for sensitive data exposure make this a significant risk or further compromise.

Generated by OpenCVE AI on September 15, 2026 at 15:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade any affected Regular Labs extensions to the latest available versions: Advanced Module Manager 12.1.0 or later, Conditional Content 8.0.0 or later, Content Templater 14.2.0 or later, and ReReplacer 16.2.0 or later.
  • If upgrading is not immediately possible, implement a whitelist on accepted table and column names or add server‑side validation to ensure only supported database fields are referenced, thereby preventing arbitrary field selection.
  • Review and tighten database permissions for the extensions to have only the minimum privileges required, and monitor logs for anomalous queries that might indicate exploitation attempts.

Generated by OpenCVE AI on September 15, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description Joomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager (Free, Pro) < 12.1.0, Conditional Content (Free, Pro) < 8.0.0, Content Templater (Pro) < 14.2.0, ReReplacer (Pro) < 16.2.0 for Joomla - The Conditions editor creates a default Condition Set name from the item to which the set is linked. The affected code accepts the database table and label-column names from the request. Although these names are quoted as SQL identifiers, they are not restricted to the tables and columns used by supported Regular Labs integrations. An attacker can therefore select a valid but unrelated database field. This is an authorization failure rather than SQL injection.
Title Joomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager (Free, Pro) < 12.1.0, Conditional Content (Free, Pro) < 8.0.0, Content Templater (Pro) < 14.2.0, ReReplacer (Pro) < 16.2.0 for Joomla
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-09-14T11:23:42.411Z

Reserved: 2026-09-03T12:01:51.928Z

Link: CVE-2026-85188

cve-icon Vulnrichment

Updated: 2026-09-14T11:14:51.428Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T07:17:22.203

Modified: 2026-09-16T19:28:06.713

Link: CVE-2026-85188

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:30:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor