Impact
An improper limitation of paths in the getSource function of Phoca Commander allows an attacker to read arbitrary files from the Joomla server. The flaw maps to CWE‑22, leading to potential exposure of sensitive configuration files, credentials, or other data stored on the web host. The impact is information disclosure, which could aid further attacks or compromise confidentiality.
Affected Systems
The vulnerability affects the Phoca Commander extension for Joomla produced by phoca.cz, in all releases from 1.0.0 up to 6.1.3. Users who have installed any of these versions are exposed unless they upgrade to a version where the path‑validation check has been corrected.
Risk and Exploitability
The issue receives a CVSS score of 8.2, indicating high severity. No EPSS data is available, and the vulnerability is not yet listed in the CISA KEV catalog. Exploitation is likely through web requests that invoke the getSource function with a crafted file path; the attack can be performed remotely if the attacker can construct an HTTP request, but it requires the extension to be active on a publicly accessible Joomla site. Given the high CVSS score and lack of mitigation by default, the risk level remains high until the extension is updated or otherwise restricted.
OpenCVE Enrichment