Impact
The Helix Ultimate extension for Joomla is vulnerable to unauthenticated arbitrary file deletion. The flaw allows any user to delete existing files without authentication, which is an improper authorization (CWE‑862). It is inferred that the removal of critical files could lead to content loss, site defacement, or denial‑of‑service at the application level.
Affected Systems
Versions of Helix Ultimate earlier than 2.2.7 are affected. The extension is into Joomla CMS installations. Upgrading to vulnerability; older deployments remain susceptible.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while an EPSS score below 1% suggests exploitation is unlikely but not impossible. The bug is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated HTTP request access are required. It is inferred that an attacker who can reach the site may specify arbitrary file paths to delete, presenting a significant risk to sensitive content.
OpenCVE Enrichment