Impact
The Zoo extension for Joomla exposes an arbitrary file upload vulnerability that permits unauthenticated users to upload any file type. When the client sends a Content-Type header within the image MIME group, the server accepts the file without validating its actual contents or type. This flaw enables an attacker to place malicious files, such as web shells, onto the server and subsequently execute them, giving full remote code execution capability.
Affected Systems
Affected are installations of the yootheme.com Zoo extension for Joomla running any version earlier than 4.1.64. No authentication is required, so the vulnerability stands in the default configuration.
Risk and Exploitability
The CVSS score of 10 indicates a complete compromise with no need for privileged access. The EPSS score of 0.00312 (less than 1%) indicates a very low but non‑zero exploitation probability, yet the lack of authentication and the ability to upload executable code means an attacker could still exploit the vulnerability. The vulnerability is not currently listed in CISA’s KEV catalog, but the severity warrants immediate attention. Attackers can exploit the flaw over the public web interface, making it a broad threat vector.
OpenCVE Enrichment