Uploading a file did not check Joomla’s form token, neither in the back end nor in the front end. A prepared page on another web site could therefore make the browser of a logged in user upload a file into any event whose folder name it knows - and replace a file of the same name there, which removes the original. Only images and videos of the allowed types can be uploaded this way; it is no way to put code onto the server.
- Needed: no account. The victim is logged in with the permission Edit of Event Gallery, in the back end additionally with Manage, and opens a prepared page.
- Affected: all versions before 6.5.0 except 4.3.3.
- Fixed in: 6.5.0 and 4.3.3. The upload needs the form token.
-
Severity: CVSS 4.0 5.1 (
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N), CWE-352. - CVE: CVE-2026-100747.
All prices include VAT. The gross price will vary depending on the selected shipping country.