Executive brief
Fabrik is a Joomla extension for building custom data applications without coding. An unauthenticated attacker can inject arbitrary SQL code through list filter parameters, allowing them to read the entire database including sensitive user data, credentials, and business information. This vulnerability affects all unauthenticated visitors to public-facing Fabrik lists.
Technical details
The vulnerability is a SQL injection flaw in the list filter functionality of Fabrik. The condition parameter passed to a list filter is concatenated directly into the WHERE clause without proper sanitization or parameterization. An unauthenticated attacker can supply arbitrary SQL through the filter condition parameter in the URL or form submission. No authentication or special privileges are required to exploit this vulnerability. The attacker can achieve full read access to the database, potentially extracting sensitive data such as user credentials, email addresses, and application-specific information. Patches are available in version 4.7.2 and later.
Affected products
- Fabrik Fabrik < 4.7.2
Timeline
- 2026-08-22: disclosed