Executive brief
The Fabrik extension for Joomla, a tool used to build custom database-driven applications and forms, contains a security flaw. An unauthenticated attacker can remotely browse and list files on the server that should be private. This could lead to the exposure of sensitive system information or configuration files, potentially aiding further attacks.
Technical details
A directory traversal vulnerability exists in the 'image' element plugin of the Joomla com_fabrik extension (specifically version 3.9.11 and likely earlier). The root cause is insufficient sanitization of the 'folder' parameter within the 'onAjax_files' method in 'fabrik_element/image/image.php'. An unauthenticated attacker can send a crafted GET request containing path traversal sequences (e.g., '../../') to the 'onAjax_files' method. This allows the attacker to bypass the intended web root restrictions and list the contents of arbitrary directories on the server's filesystem. While the vulnerability allows for file enumeration, it does not directly provide file read or write capabilities.
Affected products
- Joomla com_fabrik <= 3.9.11
Timeline
- 2020-03-30: disclosed: Initial exploit published on Exploit-DB
- 2026-05-13: advisory: NVD/VulnCheck advisory published