PT-2026-103328 · Ordasoft · Ordasoft Joomla Cck

·

CVE-2026-102427

·

Published

2026-09-30

·

Updated

2026-10-01

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y
Name of the Vulnerable Software and Affected Versions OrdaSoft Joomla CCK versions prior to 8.3.16
Description An unauthenticated remote code execution issue exists in the site/uploader.php endpoint, which is accessible via the getContent task. The system fails to perform authentication or Access Control List (ACL) checks during the dispatch process. While the handler performs a magic-byte MIME check to validate file content, the extension allow-list intended to restrict file extensions is commented out in the source code. Consequently, the application accepts the filename provided by the user without validation and saves the file directly under the Joomla web root. An attacker can upload an image/PHP polyglot—a file that satisfies the MIME check with PHP code appended—using a .php extension to execute arbitrary code on the server.
Recommendations Update OrdaSoft Joomla CCK to version 8.3.16 or later. Restrict access to the site/uploader.php endpoint as a temporary mitigation measure.

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102427

Affected Products

Ordasoft Joomla Cck