Impact
The Joomla extension RSFiles has a flaw that permits attackers to upload arbitrary files without authentication. The flaw allows executable code to be stored and later executed, giving an attacker full remote code execution capabilities. This weakness is classified as CWE-434, an untrusted upload vulnerability.
Affected Systems
The vulnerability affects the RSFiles extension for Joomla from rsjoomla.com, versions earlier than 1.17.12. Users running those older releases are exposed.
Risk and Exploitability
The CVSS score climbs to 10, indicating a critical severity. The EPSS score is <1%, a very low but nonzero probability that attackers exploit this vulnerability, though the potential impact remains high. The vulnerability is not listed in the CISA KEV catalog. The likely attack path is via the public web interface of the extension, where an unauthenticated user can submit files for upload and execute them on the server.
OpenCVE Enrichment