Executive brief
RO CSVI is a Joomla extension used for importing and exporting data across various file formats like CSV and XML. A security vulnerability in its AJAX endpoint handlers could allow an attacker to trick a logged-in administrator into performing unintended actions on the site. This could lead to unauthorized data modifications or configuration changes depending on the specific administrative functions targeted.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the rolandd.com RO CSVI extension for Joomla versions prior to 9.11.0. The flaw is located within the AJAX endpoint handlers, which fail to properly validate CSRF tokens. An attacker can exploit this by crafting a malicious webpage or link that, when visited by an authenticated administrator, triggers unauthorized requests to these endpoints. This could allow for unauthorized execution of import/export tasks or other administrative functions. Users should update to version 9.11.0 or later to remediate this issue.
Affected products
- rolandd.com RO CSVI extension for Joomla 1.0.0 to 9.11.0
Timeline
- 2026-07-29: disclosed: CVE published by Joomla! Project