Impact
An improper access check in Joomla! CMS's com_media webservice endpoints lets a logged-in privileged user overwrite media files without the typical editorial permission, resulting in unauthorized replacement of site assets. This vulnerability is a CWE-284: Improper Privilege Management, allowing privileged users to circumvent normal access controls.
Affected Systems
The flaw applies to Joomla! CMS released by the Joomla! Project; any version with the unpatched com_media endpoints is potentially affected, though no specific version range is identified.
Risk and Exploitability
The CVSS score of 6.4 denotes medium severity. The EPSS score of less than 1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. Exploitation requires an authenticated privileged account and the use of the com_media webservice to overwrite files, so the risk is confined to existing elevated‑privilege users.
OpenCVE Enrichment