CVE-2026-102427
Publiée le 2026-09-30 · Dernière modification le 2026-10-01
Les serveurs utilisant OrdaSoft Joomla CCK dans des versions antérieures à la 8.3.16 sont vulnérables à une faille dans le gestionnaire de téléchargement de fichiers. Un attaquant peut téléverser un script PHP malveillant déguisé en image vers la racine web et l'exécuter, lui octroyant ainsi le contrôle total du serveur. Cette opération peut être réalisée à distance via le réseau, sans aucune authentification ni interaction de l'utilisateur.
DÉTAIL DU VECTEUR CVSS
RÉFÉRENCES
Description officielle du NVD (en anglais)
Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s content with a real magic-byte MIME check, but the extension allow-list that would otherwise restrict the saved file’s extension was present in the source and commented out. The saved file’s extension was taken directly from the attacker-supplied filename with no validation, and the file was written to a path directly under the Joomla web root that is executed by the PHP handler. An image/PHP polyglot, a file whose header bytes satisfy the MIME check with PHP source appended after, passed the content check while carrying a .php extension of the attacker’s choosing.