Impact
The vulnerability is an improper ACL implementation in the Cotton Cloud Joomla extension version below 2.0.2. It allows unauthenticated users to perform file operations such as read, delete, overwrite, and re‑assign permissions on any file managed by the extension. This flaw falls under CWE‑284 and enables attackers to change or delete files without credentials, consequently compromising data integrity and potentially the configuration of the hosting site.
Affected Systems
The affected product is the Cotton Cloud extension for Joomla provided by tabaoca.org. All installations of the extension with a version lower than 2.0.2 are vulnerable. No other vendors or products are listed in the CNA data.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate risk, and while the EPSS score is not available, the lack of a listed KEV status suggests no confirmed exploit yet. The likely attack vector is unauthenticated web access to the extension’s endpoints, allowing an attacker to execute file operations directly through the user interface. The impact can lead to unauthorized file deletion, configuration tampering, or potential data disclosure if files include sensitive content.
OpenCVE Enrichment