Executive brief
Fabrik is a Joomla extension that allows users to build custom web applications and forms without coding. A remote code execution vulnerability in the image element could allow attackers to execute arbitrary code on the server, potentially compromising the entire website and any data stored within custom applications built with Fabrik.
Technical details
The vulnerability is a remote code execution issue in the image element handling of Fabrik versions prior to 4.7.2. The exact attack vector and root cause are not fully detailed in available sources, but the vulnerability exists in image element processing. An attacker can exploit this to execute arbitrary code on the server. The vulnerability affects Fabrik < 4.7.2, and a patch is available in version 4.7.2 and later.
Affected products
- Fabrikar Fabrik < 4.7.2
Timeline
- 2026-08-22: disclosed