Executive brief
Fabrik is a Joomla extension that allows users to build custom web applications without coding. This vulnerability allows unauthenticated attackers to enumerate arbitrary directories on the server through a method in the elements model, potentially exposing sensitive file paths and directory structures that could facilitate further attacks.
Technical details
The vulnerability exists in the onAjax_getFolders method of Fabrik's elements model, which fails to properly validate or restrict directory listing requests. An unauthenticated attacker can invoke this AJAX method over the network without authentication to retrieve directory listings of arbitrary paths on the server. The vulnerability affects Fabrik versions prior to 4.7.2. While the impact is primarily informational (directory enumeration), it can enable reconnaissance for subsequent attacks targeting sensitive files or directories.
Affected products
- fabrikar.com Fabrik < 4.7.2
Timeline
- 2026-08-22: disclosed