PT-2026-95996 · Ordasoft · Ordasoft Joomla Gallery
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
OrdaSoft Joomla Gallery versions prior to 6.2.7
Description
An authenticated and privileged remote code execution issue exists in the OrdaSoft Joomla Gallery extension. The
updateOSGallery() function, accessible via the task=update osgallery parameter, processes a JSON request body and executes the value provided in the method field as a PHP function. The value from the package field is then passed as the single argument to that function. Because the extension lacks an allow-list or is callable() check, any PHP function accepting one argument can be executed, including system, exec, shell exec, and passthru.Recommendations
Update OrdaSoft Joomla Gallery to version 6.2.7 or later.
As a temporary workaround, restrict access to the
task=update osgallery functionality to minimize the risk of exploitation.Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ordasoft Joomla Gallery