CyberRota Analysis
AI-GeneratedThe Joomla Extension from fabrikar.com is vulnerable to unauthenticated arbitrary file uploads through the list email plugin in versions prior to 4.7.2, allowing attackers to upload non-executable files to the web root. This could lead to potential exploitation, including data exposure or further attacks on the web application. Joomla administrators and users of the Fabrik extension should prioritize patching to mitigate this high-severity vulnerability.
Original NVD Description
Joomla Extension - fabrikar.com - Unauthenticated arbitrary file upload to web root via list email plugin in Fabrik < 4.7.2 - The list email plugin controller allows to upload non-executable files to the webroot.