Impact
The Joomla extension JDownloads by dj-extensions.com enables attackers to upload arbitrary files without authentication via the public upload interface. The uploaded file is then executed with the same privileges as the web application, granting full remote code execution on the site. This issue is a classic uncontrolled file upload vulnerability, identified as CWE‑434.
Affected Systems
All releases of the jDownloads extension from dj-extensions.com before version 4.1.6 are vulnerable. The flaw exists in the extension distributed for Joomla and is present in every pre‑4.1.6 build. Upgrading to 4.1.6 or later removes the vulnerability.
Risk and Exploitability
The CVSS score of 10 indicates a critical impact, and the EPSS score of <1% suggests a relatively low but non‑zero likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog, yet its high severity and simple exploitation path make it attractive to attackers. The vulnerability can be triggered from any network location that can access the Joomla site’s public upload interface, providing an unauthenticated and externally visible attack vector.
OpenCVE Enrichment