CyberRota Analysis
AI-GeneratedThe vulnerability allows unauthenticated users to delete arbitrary installed extensions in the free versions of miniOrange plugins for Joomla due to a lack of authentication checks. This could lead to significant disruptions in website functionality and potential data loss for affected sites. Joomla administrators using the free miniOrange extensions should prioritize remediation to mitigate the risk of unauthorized extension deinstallation.
Original NVD Description
Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension deinstallation via various miniOrange extensions - a missing authentication check allows unauthenticated actors to delete arbitrary installed extensions. Only the free versions of the miniOrange plugins are affected.