4.3.3

This is a security release for sites which run Event Gallery 4 on Joomla 3 or Joomla 4. Update them to 4.3.3. It brings the fixes of Event Gallery 6.5.0 for four vulnerabilities to the 4.3 line and changes nothing else. All versions of Event Gallery before 4.3.3 are affected. The chapter Security Advisories of the current manual on www.svenbluege.de describes every vulnerability in detail.

4.3.3 is a one-time exception: security fixes are made for the current version of Event Gallery only, so there will be no further fixes for Joomla 3 and Joomla 4. Plan the update to Joomla 5.4 or later and Event Gallery 6.5.0.

Security Fixes
  • Path traversal in Clear Cache (EGSA-2026-01, CVE-2026-97164, severity 7.0). Event Gallery → Clear Cache took the name of the cache folder to empty from the request and did not check where it led. A back-end user with the permission to manage Event Gallery - in Joomla’s default permissions every Administrator, not only a Super User - could make it delete any folder the web server may write to, up to the whole site. It now only empties a folder which lies directly in the image cache.
  • Cross-site scripting and open redirect on the front-end upload page (EGSA-2026-02, CVE-2026-97165, severity 5.3). The Back link of the upload page of the front end took its target from the address of the page and printed it as it came. A prepared link could therefore make it point to another web site, or run a script in the session of the editor who opened it. The link now only leads to a page of your own site, and there is none when the address names anything else.
  • Forged uploads (EGSA-2026-03, CVE-2026-100747, severity 5.1). Uploading a file did not check the security token, neither in the back end nor in the front end, so a prepared page on another web site could make a logged in editor upload a file into an event - and replace a file of the same name there. The upload now needs the token.
  • Forged clean-up in the back end (EGSA-2026-05, CVE-2026-100749, severity 5.1). The two clean-up links on the overview page of the backend, which remove orphaned files and old carts from the database, now carry Joomla’s form token. Before, a prepared link on another website could have triggered them while you were logged in to the backend.

Not part of 4.3.3: the forged cart changes (EGSA-2026-04, CVE-2026-100748, severity 6.9), because the fix needs new scripts in the cart. The buyer sees the cart before an order is placed. It is fixed in Event Gallery 6.5.0.

Migration Hints
  • If you have a template override of the upload page of the back end (upload/default.php of com_eventgallery in your administrator template), or an override of the upload page of the front end which copied that markup instead of including the file of the back end, bring it up to date: the address in the attribute data-upload-url of the element #uploader now carries the security token. With an old override every file is refused with the message about an invalid security token.
  • If you have a template override of upload/default.php of the front end, it gets the checked target of the Back link from the view; take over the escaping of the link from the new file.
All prices include VAT. The gross price will vary depending on the selected shipping country.