EGSA-2026-03: Cross-site request forgery of the upload

Uploading a file did not check Joomla’s form token, neither in the back end nor in the front end. A prepared page on another web site could therefore make the browser of a logged in user upload a file into any event whose folder name it knows - and replace a file of the same name there, which removes the original. Only images and videos of the allowed types can be uploaded this way; it is no way to put code onto the server.

  • Needed: no account. The victim is logged in with the permission Edit of Event Gallery, in the back end additionally with Manage, and opens a prepared page.
  • Affected: all versions before 6.5.0 except 4.3.3.
  • Fixed in: 6.5.0 and 4.3.3. The upload needs the form token.
  • Severity: CVSS 4.0 5.1 (CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N), CWE-352.
  • CVE: CVE-2026-100747.
All prices include VAT. The gross price will vary depending on the selected shipping country.