→ took the name of the image cache folder to empty from the request (parameter images of the task cache.process) and cleaned it with a function which keeps dots and slashes. A name like ../../.. therefore led out of the cache, and Event Gallery deleted that folder with everything in it - any folder the web server may write to, up to the whole Joomla site.
- Needed: a back-end login with the permission Manage of Event Gallery. In Joomla’s default permissions that is every Administrator, not only a Super User. The request needs the form token of that login, so it can not be forged from another web site.
- Affected: all versions before 6.5.0 except 4.3.3.
- Fixed in: 6.5.0 and 4.3.3. Only a folder which lies directly in the image cache is accepted.
-
Severity: CVSS 4.0 7.0 (
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N), CWE-22. - CVE: CVE-2026-97164.
All prices include VAT. The gross price will vary depending on the selected shipping country.