Executive brief
Multiple Regular Labs extensions for the Joomla content management system fail to properly validate security tokens and user permissions within their administration interfaces. These extensions are used to manage how content and modules are displayed on a website. An attacker could potentially bypass security checks to modify site configurations or content settings, leading to unauthorized changes to the website's behavior or appearance.
Technical details
Multiple Regular Labs extensions for Joomla (Advanced Module Manager, Conditional Content, Content Templater Pro, and ReReplacer Pro) are vulnerable to improper access control (CWE-284) and Cross-Site Request Forgery (CWE-352). The vulnerability exists within the 'conditions' administration interface, where the software fails to consistently enforce security tokens and verify component or mapped-item permissions. A remote attacker could exploit this to perform unauthorized administrative actions or modify configuration settings if they can trick an authenticated administrator into visiting a malicious link or if they can bypass the inconsistent permission checks. Affected versions range across several products, generally covering versions from 1.0.0 up to the specific patched releases identified in the advisory.
Affected products
- Regular Labs Advanced Module Manager extension for Joomla 1.0.0-11.0.1
- Regular Labs Conditional Content extension for Joomla 1.0.0-6.0.0
- Regular Labs Content Templater Pro extension for Joomla 1.0.0-13.0.0
- Regular Labs ReReplacer extension Pro for Joomla 1.0.0-15.0.3
Timeline
- 2026-07-22: disclosed: CVE published by Joomla! Project via NVD