Impact
The flaw is a broken access control (CWE‑284) in the Quix Page Builder Pro extension for Joomla. Authenticated users can upload media files even if they lack media‑management permissions, undermining the integrity of the site’s media library and potentially allowing the addition of malicious content. While the description does not explicitly state that executable files can be uploaded, the ability to upload arbitrary files suggests that attackers could choose to upload harmful files if they wish.
Affected Systems
Vulnerable installations are those running the Quix Page Builder Pro extension from themexpert.com on Joomla, with a version older than 6.2.1. Sites that rely on this extension for page building and have not applied the update remain affected.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score is less than 1%, suggesting exploitation is presently rare, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an authenticated user with access to the extension’s web interface; no external or unauthenticated vector is disclosed.
OpenCVE Enrichment