Executive brief
Multiple Regular Labs extensions for the Joomla content management system contain a security flaw in how they handle image URLs. An attacker can provide a malicious link that forces the website to communicate with internal network services or download unauthorized files. This could lead to the exposure of private internal data or the placement of malicious files on the web server.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the Regular Labs Articles Anywhere Pro and Users Anywhere Pro extensions for Joomla. The software fails to properly validate user-supplied image URLs, allowing them to request private or reserved network services and follow unsafe redirects. Furthermore, the application saves responses without verifying that the retrieved content is actually an image. This can be exploited by a remote attacker to access internal-only data or write attacker-controlled files into web-accessible directories on the server.
Affected products
- Regular Labs Articles Anywhere Pro extension for Joomla 1.0.0-18.0.2
- Regular Labs Users Anywhere Pro extension for Joomla 1.0.0-1.2.7
Timeline
- 2026-07-23: disclosed: CVE published by Joomla! Project