PT-2026-95999 · Ordasoft · Ordasoft Joomla Gallery
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
OrdaSoft Joomla Gallery versions prior to 6.2.7
Description
An authenticated user with
core.manage privileges can achieve remote code execution. The saveWatermark() function copies uploaded files into a web-accessible directory using the client-supplied filename without performing extension checks, content verification, or filename sanitization. This allows an attacker to upload a .php file by disguising it with an image Content-Type header and subsequently execute it by requesting the file path.Recommendations
Update OrdaSoft Joomla Gallery to version 6.2.7 or later.
As a temporary mitigation, restrict access to the
saveWatermark() function for users with core.manage privileges until the update is applied.Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ordasoft Joomla Gallery