PT-2026-65790 · Joomla · Joomla Content Editor
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Joomla Content Editor (JCE) versions prior to 2.20.2
Description
Improper input validation in the file rename functionality allows an authenticated user with file management permissions to rename files using invalid names. This can lead to the creation of hidden files and the unintended replacement of existing files at the destination path.
Recommendations
Update Joomla Content Editor (JCE) to version 2.20.2 or later.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Joomla Content Editor