Impact
The Joomla extension DJ-Classifieds contains an unauthenticated file upload flaw that permits any visitor to upload arbitrary files, including executable scripts, which the application serves directly. This weakness, classified as CWE-434, effectively gives attackers full remote code execution capability on the affected server.
Affected Systems
DJ-Classifieds, the Joomla extension from dj-extensions.com, is impacted in all releases prior to version 3.11.2.
Risk and Exploitability
The flaw carries a CVSS score of 10, indicating maximum severity. Exploitation requires unauthenticated access to the upload endpoint. The EPSS score is below 1 %, reflecting a low current exploitation likelihood, but the high severity and absence of protective controls present a significant risk if the vulnerability remains unpatched. The vulnerability is not listed in the CISA KEV catalog, yet the potential for widespread abuse remains high should an attacker target a site running the affected extension.
OpenCVE Enrichment