CVE-2026-64791
N/A
N/A
Summary
Administrator routes and install/update/uninstall processing did not consistently enforce component-management and installation permissions. An unauthorized backend user or CSRF attack could install, update or remove extensions.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| regularlabs.com | Regular Labs Extension Manager extension for Joomla | 1.0.0-9.2.5 | affected |
Weaknesses
- CWE-352: CWE-352 Cross-Site Request Forgery (CSRF)
- CWE-284: CWE-284 Improper Access Control
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.