PT-2026-103328 · Ordasoft · Ordasoft Joomla Cck
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y |
Name of the Vulnerable Software and Affected Versions
OrdaSoft Joomla CCK versions prior to 8.3.16
Description
An unauthenticated remote code execution issue exists in the
site/uploader.php endpoint, which is accessible via the getContent task. The system fails to perform authentication or Access Control List (ACL) checks during the dispatch process. While the handler performs a magic-byte MIME check to validate file content, the extension allow-list intended to restrict file extensions is commented out in the source code. Consequently, the application accepts the filename provided by the user without validation and saves the file directly under the Joomla web root. An attacker can upload an image/PHP polyglot—a file that satisfies the MIME check with PHP code appended—using a .php extension to execute arbitrary code on the server.Recommendations
Update OrdaSoft Joomla CCK to version 8.3.16 or later.
Restrict access to the
site/uploader.php endpoint as a temporary mitigation measure.Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ordasoft Joomla Cck