Impact
The flaw resides in Joomla! CMS com_joomlaupdate's extraction routine, allowing a Super User to extract a ZIP archive containing directory traversal or absolute path entries. When processed, these entries cause files to be written outside the intended destination, enabling an attacker to drop arbitrary files—including PHP scripts—into web‑accessible locations. If executed, the attacker gains persistent remote code execution and full site compromise.
Affected Systems
Joomla! CMS version 6.1.1 is affected through the com_joomlaupdate component. No other versions are listed as vulnerable. The issue applies to administrators with Super User rights who handle update archives via the update interface.
Risk and Exploitability
The CVSS score of 8.7 denotes a high severity. EPSS is not available, and the vulnerability is not in the CISA KEV catalog, yet the potential for remote code execution remains serious. Exploitation requires inducing a Super User to extract a malicious archive, limiting the attack surface to privileged users, but the impact once successful is full compromise. Immediate patching is strongly recommended.
OpenCVE Enrichment