Impact
The vulnerability resides in the Phoca Commander extension for Joomla, affecting versions 1.0.0 through 6.1.3. The file upload routine does not properly constrain paths, allowing an attacker to specify a path that resolves outside the intended upload directory. This path‑traversal flaw permits writing files to arbitrary locations on the Joomla installation, which could be used to place malicious scripts or modify existing files.
Affected Systems
Affected systems are Joomla websites that have the Phoca Commander extension installed in any of the vulnerable versions. Administrators should verify the product version and upgrade to a fixed release.
Risk and Exploitability
The CVSS base score of 6.1 indicates moderate severity; the EPSS score is not available and the issue is not listed in KEV. Attackers could remotely exploit this via the web interface that exposes the file upload endpoint, assuming they have permission to perform uploads. The lack of a public exploit does not preclude potential attacks; as a path‑traversal flaw, it may enable arbitrary file modification or code execution if the uploaded file is placed in a web‑executable directory.
OpenCVE Enrichment