Executive brief
Fabrik is a Joomla extension that enables users to create custom data applications without coding. An unauthenticated attacker can modify any comment in the system through an unprotected endpoint, potentially allowing vandalism, data tampering, or unauthorized alterations to user-generated content.
Technical details
The onUpdateComment endpoint in Fabrik versions before 4.7.2 lacks proper access control checks, allowing unauthenticated requests to modify comments. The vulnerability stems from insufficient authorization validation when processing comment updates. An attacker can send a crafted request to the endpoint without authentication to modify arbitrary comments. The attack requires network access to the Fabrik instance but no prior authentication or user interaction. Affected versions are Fabrik < 4.7.2; a patch is available in version 4.7.2 and later.
Affected products
- Fabrik Fabrik < 4.7.2
Timeline
- 2026-08-22: disclosed