Executive brief
Two popular Joomla extensions used for displaying content and user information contain a security flaw that allows unauthorized access to sensitive data. By using specially crafted content, an attacker could view restricted user details, raw system parameters, or authentication-related information. This could lead to the exposure of private contact information or data that assists in further compromising user accounts.
Technical details
An improper access control vulnerability (CWE-284) exists in the Regular Labs Articles Anywhere and Users Anywhere extensions for Joomla. The issue stems from user tags, filters, and conditions that do not sufficiently restrict access to sensitive user fields. A remote attacker can exploit this by crafting specific content that triggers these components to expose authentication-related data, raw user parameters, or restricted contact details. The vulnerability affects Articles Anywhere versions 1.0.0 through 18.0.2 and Users Anywhere versions 1.0.0 through 1.2.7.
Affected products
- Regular Labs Articles Anywhere extension for Joomla 1.0.0 through 18.0.2
- Regular Labs Users Anywhere extension for Joomla 1.0.0 through 1.2.7
Timeline
- 2026-07-22: disclosed
- 2026-07-22: advisory