CyberRota Analysis
AI-GeneratedThe Joomla extension from fabrikar.com is vulnerable to unauthenticated table truncation due to insufficient access control in the list.doempty endpoint, allowing an attacker to execute a simple GET request to empty the target list's table. This vulnerability poses a high risk as it can lead to data loss and disruption of services for affected Joomla installations. Organizations using Fabrik versions prior to 4.7.2 should prioritize immediate updates to mitigate this risk.
Original NVD Description
Joomla Extension - fabrikar.com - Unauthenticated table truncation via list.doempty in Fabrik < 4.7.2- The list controllers doemtpy endpoints lacks ACL gates, a plain GET empties the target list's table