Impact
The Page Builder CK extension for Joomla allows authenticated users to upload files without proper validation, enabling arbitrary code execution. This flaw corresponds to CWE-434 and can fully compromise confidentiality, integrity, and availability once exploited.
Affected Systems
Joomla sites using the joomlack.fr Page Builder CK extension, any version earlier than 3.6.2, are affected. The vulnerability was reported for all instances that have not applied the update.
Risk and Exploitability
The CVSS base score of 9.4 categorizes the issue as critical. The EPSS score of less than 1% suggests that exploit attempts are currently rare, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers must first gain authenticated access—such as administrators or users with content‑creation privileges—to upload a malicious file via the Page Builder CK extension. Once the file is uploaded, it can be executed directly, giving the attacker full control over the affected web server. The high severity and the inferred authenticated‑only attack path mean that a successful exploit would immediately provide an attacker with complete control of the target web server.
OpenCVE Enrichment