PT-2026-61680 · Joomla · Jmedia
CVE-2026-60033
·
Published
2026-07-20
·
Updated
2026-07-20
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
JMedia versions prior to 1.6.0
Description
The JMedia extension for Joomla contains a Server-Side Request Forgery (SSRF) flaw. This issue allows a remote-URL download feature to be used to target internal or reserved network addresses, potentially exposing internal services.
Recommendations
Update JMedia to version 1.6.0 or later.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jmedia