PT-2026-76726 · Regular · Sourcerer
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Regular Labs Sourcerer versions prior to 14.0.0
Description
An unauthenticated remote code execution (RCE) issue exists because the software processes
{source} blocks found in the final rendered HTML of Joomla without reliably determining the origin of the code. This allows for the execution of arbitrary code through unverified reflected user input.Recommendations
Update Regular Labs Sourcerer to version 14.0.0 or later.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sourcerer