CyberRota Analysis
AI-GeneratedAn improper access control vulnerability allows unauthorized users to download vCard exports of contacts from the com_contact component, potentially exposing sensitive information. This high-severity issue could lead to data leakage and privacy violations. Organizations utilizing this component should prioritize remediation to protect user data and maintain compliance with privacy regulations.
CVE
CVE-2026-48948
Severity
HIGH
CVSS
8.8
EPSS
0.24%
Original NVD Description
An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
Related CVEs
Other vulnerabilities affecting the same vendor(s)