Impact
The vulnerability allows an attacker who can access the Joomla site to create directories without authentication. The flaw stems from improper access control in the RO CSVI extension, identified as CWE‑284.
Affected Systems
Any installation of the RO CSVI extension from rolandd.com running Joomla, with affected versions older than 9.11.0.
Risk and Exploitability
The CVSS score is 7.5, indicating a moderate to high severity. The EPSS score is less than 1 %, suggesting a very low likelihood of exploitation at present, and the issue is not listed in the CISA KEV catalog. The flaw can be exploited from the web application without user authentication.
OpenCVE Enrichment