Executive brief
The GeoIP extension for Joomla, a tool used to identify the geographic location of website visitors, contains a security flaw in how it handles database updates. An attacker could potentially trigger unauthorized changes to the database because the software fails to properly verify administrative permissions and security tokens. This could lead to unauthorized data modification or system instability.
Technical details
The GeoIP extension for Joomla (versions 1.0.0 through 6.3.8) fails to consistently perform Super User permission checks and anti-CSRF token validation during database-update requests. This vulnerability is classified under CWE-284 (Improper Access Control) and CWE-352 (Cross-Site Request Forgery). A remote attacker could potentially exploit this by tricking an authenticated administrator into visiting a malicious site or by sending crafted requests that bypass authorization logic. Successful exploitation allows for unauthorized updates to the extension's database components.
Affected products
- Regular Labs GeoIP extension for Joomla 1.0.0 through 6.3.8
Timeline
- 2026-07-23: disclosed: CVE published by Joomla! Project