Impact
The Joomla extension Phoca Downloads, version earlier than 6.1.3, permits authenticated users to upload arbitrary files. Because the component does not restrict file types, an attacker can upload executable scripts that are processed by the web server, thus achieving full remote code execution on the Joomla site and the underlying web server. This vulnerability is a file upload flaw, classified as CWE‑434.
Affected Systems
The flaw affects sites running the Phoca Download extension for Joomla provided by phoca.cz, specifically any installation of the component older than version 6.1.3. Any Joomla website that has this extension installed and allows registered users to upload files is at risk. The vulnerability is not listed in the CISA KEV catalog.
Risk and Exploitability
The CVSS score of 9 indicates critical severity. The EPSS score of < 1 % shows a very low likelihood of exploitation, although the attack requires only authenticated access to the site’s upload interface. The likely attack vector is an authenticated user exploiting the upload feature of the Phoca Downloads component to place a malicious file on the server which is then executed with the web server’s privileges.
OpenCVE Enrichment