Executive brief
The Regular Labs GeoIP extension for Joomla, which provides geolocation services for websites, was found to leak MaxMind credentials within request URLs. This flaw could allow unauthorized parties to intercept sensitive API keys or login details used to access geolocation data. Exposure of these credentials could lead to unauthorized use of the MaxMind service or potential account compromise.
Technical details
A sensitive information disclosure vulnerability (CWE-200) exists in the Regular Labs GeoIP extension for Joomla versions 1.0.0 through 6.3.8. The extension transmits MaxMind credentials as part of the request URL, making them visible in web server logs, browser history, and potentially to network intermediaries. An attacker with access to these logs or network traffic could extract the credentials to gain unauthorized access to the associated MaxMind account or services. The issue was reported by the Joomla! Project and affects the GeoIP geolocation library component.
Affected products
- Regular Labs GeoIP extension for Joomla 1.0.0 through 6.3.8
Timeline
- 2026-07-23: disclosed: CVE published to NVD dataset