PT-2026-61679 · Joomla · Jmedia
CVE-2026-60032
·
Published
2026-07-20
·
Updated
2026-07-20
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
JMedia versions prior to 1.6.0
Description
The Joomla extension JMedia allows authenticated users to perform arbitrary file uploads, which can lead to Remote Code Execution (RCE). This occurs because the system permits the upload and writing of executable files, including those with polyglot filenames, and the
chmod function fails to strip execute bits from the uploaded files.Recommendations
Update JMedia to version 1.6.0 or later.
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jmedia