Impact
An improperly secured file management feature in Astroid Template Framework allows unauthenticated users to upload dangerous data types. The uploaded content can then be executed, leading to remote code execution on the affected system.
Affected Systems
The vulnerability affects Astroid Template Framework for Joomla, specifically versions 2.0.0 through 3.3.10.
Risk and Exploitability
The CVSS score of 10 marks the flaw as critical, while the EPSS score of less than 1% suggests that widespread exploitation is currently unlikely. The flaw is not listed in the CISA KEV catalog, but because the attack does not require authentication, an attacker can trigger it from any location. If successfully exploited, the attacker would gain the ability to execute arbitrary code on the host, compromising confidentiality, integrity, and availability of the Joomla instance.
OpenCVE Enrichment