FICHE CVE

CVE-2026-102427

Publiée le 2026-09-30 · Dernière modification le 2026-10-01

🇫🇷 EN BREF

Les serveurs utilisant OrdaSoft Joomla CCK dans des versions antérieures à la 8.3.16 sont vulnérables à une faille dans le gestionnaire de téléchargement de fichiers. Un attaquant peut téléverser un script PHP malveillant déguisé en image vers la racine web et l'exécuter, lui octroyant ainsi le contrôle total du serveur. Cette opération peut être réalisée à distance via le réseau, sans aucune authentification ni interaction de l'utilisateur.

Publiée2026-09-30
Dernière modification2026-10-01

DÉTAIL DU VECTEUR CVSS

Vecteur d'attaqueRéseau
Complexité d'attaqueFaible
Prérequis d'attaqueAucun
Privilèges requisAucun
Interaction utilisateurAucune
Confidentialité (système vulnérable)Élevée
Intégrité (système vulnérable)Élevée
Disponibilité (système vulnérable)Élevée
Confidentialité (système subséquent)Élevée
Intégrité (système subséquent)Élevée
Disponibilité (système subséquent)Élevée
Maturité de l'exploitAttaquée
AutomatisableOui

RÉFÉRENCES

Description officielle du NVD (en anglais)

Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s content with a real magic-byte MIME check, but the extension allow-list that would otherwise restrict the saved file’s extension was present in the source and commented out. The saved file’s extension was taken directly from the attacker-supplied filename with no validation, and the file was written to a path directly under the Joomla web root that is executed by the PHP handler. An image/PHP polyglot, a file whose header bytes satisfy the MIME check with PHP source appended after, passed the content check while carrying a .php extension of the attacker’s choosing.