PT-2026-99781 · Joomla · Modules Anywhere
CVE-2026-100750
·
Published
2026-09-28
·
Updated
2026-09-30
CVSS v4.0
8.5
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Modules Anywhere versions 1.5.0 through 9.0.5
Description
Modules Anywhere Pro allows additional attributes on a module tag to replace arbitrary parameters of the selected module, a feature enabled by default. These overrides are applied without verifying the author of the content containing the tag. The impact depends on how the selected module processes the replaced parameter. For instance, the Joomla core Feed module is affected via its
rssurl parameter, which the server opens and allows to contain both local file and network URLs, potentially leading to Local File Inclusion (LFI) or Server-Side Request Forgery (SSRF).Recommendations
Update Modules Anywhere to a version later than 9.0.5.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Modules Anywhere