CVE-2026-76571
Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.2
CRITICAL
Extension Joomla — fabrikar.com
Source officielle
Description
Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.2 - The condition parameter passed to a list filter is concatenated verbatim into the WHERE clause built by getFilterQuery(). An unauthenticated attacker can supply arbitrary SQL through the filter condition, giving full read of the database.
Sévérité
9.3
Critique · CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Score retenu : NVD
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| NVD | CRITICAL | 9.3 (v4.0) |
Produit et versions
- Produit
- Extension Joomla — fabrikar.com
- Corrigée dans
- Non précisée
- Publiée
- 22/08/2026
- Modifiée
- 26/08/2026
- CWE
- CWE-89
Versions concernées
- Fabrik extension for Joomla — 1.0.0 – 4.7.1
Sources
- NVD CNA Joomla CVE-2026-76571 vu
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Détectée via nvd26/09/2026 09:34 UTC