Executive brief
Fabrik is a Joomla component that enables users to build custom applications and data management systems without coding. The list email plugin in Fabrik versions before 4.7.2 allows unauthenticated attackers to upload arbitrary files to the web server's root directory, potentially enabling code execution and site compromise.
Technical details
The vulnerability exists in the list email plugin controller, which fails to properly restrict file uploads by authentication or file type validation. An attacker can send crafted requests to the upload endpoint without authentication to place non-executable files in the webroot. While the restriction to non-executable files provides some protection, uploaded files could still be chained with other techniques or misconfigurations to achieve code execution, or used for credential harvesting or malware distribution. The issue is fixed in Fabrik version 4.7.2 and later.
Affected products
- fabrikar.com Fabrik < 4.7.2
Timeline
- 2026-08-22: disclosed