Impact
The Joomla extension Page Builder CK for Joomla contains an unrestricted file upload flaw (CWE-434) that permits unauthenticated users to upload arbitrary files, including executable scripts, which are then executed by the web server. Attackers can therefore achieve full remote code execution on the host system.
Affected Systems
All installations of the joomlack.fr Page Builder CK extension for Joomla that are running any version prior to 3.6.0 are vulnerable.
Risk and Exploitability
The vulnerability scores a CVSS of 10.0. Its EPSS score of 3% indicates a low probability of exploitation, although the unauthenticated exploitation path is listed in the CISA KEV catalog. Based on the description, it is inferred that attackers could send crafted HTTP requests to the extension's upload endpoint, upload malicious scripts, and then trigger their execution with the web server’s privileges.
OpenCVE Enrichment