Executive brief
Regular Labs Modules Anywhere, a Joomla extension used to embed modules within content, contains a security flaw in its editor popup. An authenticated user could potentially view restricted module data they are not authorized to see. This occurs because the system fails to properly verify user permissions or request tokens when displaying information in the editor interface.
Technical details
An improper access control and cross-site request forgery (CSRF) vulnerability exists in the Regular Labs Modules Anywhere extension for Joomla (versions 1.0.0 through 8.4.1). The editor popup component fails to adequately validate session tokens or specific module-level permissions before displaying data. An authenticated attacker could exploit this to access restricted module information that should be inaccessible to their user role. The vulnerability is tracked as CWE-284 and CWE-352.
Affected products
- Regular Labs Modules Anywhere extension for Joomla 1.0.0 through 8.4.1
Timeline
- 2026-07-23: advisory: NVD published the CVE record based on Joomla! Project data.