Description
Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.
Published: 2026-07-11
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Phoca Downloads component for Joomla permits authenticated users to upload arbitrary files because the file‑type validation is absent. This flaw, identified as CWE‑434, allows the upload of executable scripts. When a user uploads such a file via the RSFiles interface, the code runs with the web server’s privileges, giving the attacker full control over the Joomla installation and potentially the underlying operating system.

Affected Systems

The vulnerability applies to the Phoca Download extension for Joomla where the RSFiles component is dated earlier than version 6.1.3. Any Joomla site that has this extension installed and allows registered users to upload files through RSFiles is at risk. The flaw is not listed in CISA’s KEV catalog.

Risk and Exploitability

The flaw carries a CVSS score of 9, indicating critical severity. The EPSS score of <1% shows a very low likelihood of actual exploitation, although the attack requires only authenticated access and a standard web file‑upload form. Based on the description, the likely attack vector is authenticated use of the RSFiles upload interface, where an attacker with valid Joomla credentials uploads a malicious file that is then executed by the server.

Generated by OpenCVE AI on July 31, 2026 at 12:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Phoca Downloads component to version 6.1.3 or newer, which removes the unrestricted file‑type check.
  • Reconfigure the component to restrict allowed file extensions to safe types (e.g., only images or documents) and limit upload permissions to the minimum trusted administrators.
  • If an upgrade is not immediately possible, disable or uninstall the Phoca Downloads extension until a patched version can be applied.

Generated by OpenCVE AI on July 31, 2026 at 12:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE. Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Phoca
Phoca phoca Download Extension For Joomla
Vendors & Products Phoca
Phoca phoca Download Extension For Joomla

Sat, 11 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.
Title Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Phoca Phoca Download Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-23T14:58:47.235Z

Reserved: 2026-06-25T16:55:04.094Z

Link: CVE-2026-57828

cve-icon Vulnrichment

Updated: 2026-07-13T15:42:39.313Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:45:03Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type