CVE-2026-64799
N/A
N/A
Summary
Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they were images. This could result in SSRF, internal-data access or writing attacker-controlled files into a web-accessible folder.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| regularlabs.com | Articles Anywhere Pro extension for Joomla | 1.0.0-18.0.2 | affected |
| regularlabs.com | Users Anywhere Pro extension for Joomla | 1.0.0-1.2.7 | affected |
Weaknesses
- CWE-918: CWE-918: Server-Side Request Forgery (SSRF)
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.