CVE-2026-100750 Joomla Modules Anywhere 本地文件包含/SSRF漏洞
影响攻击者可读取服务器本地文件或发起服务端请求
Joomla 扩展 Modules Anywhere(Regular Labs 出品)在 1.5.0 至 9.0.5 版本中存在本地文件包含(LFI)与服务端请求伪造(SSRF)漏洞。该扩展允许模块标签上的附加属性覆盖所选模块的任意参数,且默认开启,覆盖时未校验内容作者身份。当被覆盖的参数被模块用于服务端请求时,即可触发文件读取或内网探测。
影响范围
受影响组件为 Regular Labs 的 Modules Anywhere(含 Pro)1.5.0 至 9.0.5 版本,运行于 Joomla 环境。具体修复版本暂无公开信息。
漏洞详情
漏洞类型为 LFI/SSRF。成因是 Modules Anywhere 允许在模块标签中附加属性以覆盖目标模块的参数,且默认启用、不校验标签内容作者。攻击者可借此覆盖 Joomla 核心 Feed 模块的 rssurl 参数,该参数由服务器端打开,并接受 file: 本地文件 URL 及网络 URL,从而读取本地文件或向任意地址发起请求。
利用条件与风险
利用前提是目标站点安装受影响版本的 Modules Anywhere 且相关功能保持默认开启,攻击者需能提交含模块标签的内容。实战中可导致敏感文件泄露与内网 SSRF 探测,风险较高。
修复建议
官方修复方案暂无公开信息,建议关注 Regular Labs 官方公告并升级至修复版本。临时缓解措施包括禁用模块标签属性覆盖功能、限制内容提交权限,以及对 rssurl 等参数做白名单校验。
Joomla Extension – regularlabs.com – LFI / SSRF in Modules Anywhere 1.5.0 – 9.0.5 for Joomla – Modules Anywhere Pro lets additional attributes on a module tag replace arbitrary parameters of the selected module. This feature is enabled by default in affected versions. The overrides are applied without checking who authored the content containing the tag. The security effect depends on how the selected module consumes the replaced parameter. Joomla’s core Feed module provides a concrete affected path: its rssurl parameter is opened by the server and accepts local file: URLs as well as network URLs.