Impact
The Helix Ultimate extension for Joomla, prior to version 2.2.7, contains a flaw that allows an attacker to delete arbitrary files without authentication. This improper authorization (CWE‑862) enables removal of site files, which could lead to loss of content, defacement, or denial‑of‑service at the application level.
Affected Systems
Versions of Helix Ultimate earlier than 2.2.7 are affected. The extension is into Joomla CMS installations. Upgrading to vulnerability; older deployments remain susceptible.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while an EPSS score below 1% suggests exploitation is unlikely but not impossible. The bug is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated HTTP request. It is inferred that an attacker who can reach the site may specify arbitrary file paths to delete, presenting a significant risk to sensitive content.
OpenCVE Enrichment