Impact
The Helix3 extension for Joomla contains a flaw in an AJAX handler that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files, and update template parameters. This authorization weakness (CWE‑284) compromises the integrity of site files and configuration, potentially disabling site functionality or paving the way for further compromise. The vulnerability does not directly expose sensitive data, but it endangers the Joomla site’s stability and trustworthiness.
Affected Systems
All installations of the Helix3 extension for Joomla are affected, regardless of the specific release, because the description does not restrict the impact to a particular product version.
Risk and Exploitability
The likely attack vector is sending unauthenticated HTTP requests to the Helix3 AJAX endpoint with crafted task parameters that trigger file deletion or creation. The CVSS score of 7.5 indicates a high severity level, and the EPSS score of 18% highlights a moderate probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, but the lack of authentication requirements and the potential for site destabilization or compromise make it a serious risk.
OpenCVE Enrichment