Impact
The vulnerability is an improper implementation of access‑control lists that permits an authenticated Joomla user to carry out file operations—such as reading, deleting, overwriting, or changing permissions—on files owned by other users. This flaw effectively allows one user to tamper with another user’s stored files, potentially compromising data integrity and confidentiality within the Cotton Cloud extension.
Affected Systems
The issue affects the Cotton Cloud extension for Joomla provided by tabaoca.org. Versions earlier than 2.0.3 are vulnerable. Updating to 2.0.3 or later eliminates the weakness.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium‑severity impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to authenticate through Joomla; once logged in, the attacker can exploit the broken ACL checks to manipulate files belonging to other users, making the attack straightforward for any user with valid credentials.
OpenCVE Enrichment