Impact
This vulnerability exists in the Joomla Event Manager extension, version 5.0.0 and earlier, where the administrator source model permits uploading files of dangerous types, including PHP. An attacker with administrative privileges can upload a malicious PHP script, which then executes under the web server’s privileges, resulting in complete remote code execution. The weakness is a file upload input validation flaw, identified as CWE‑434. The impact is a full compromise of affected sites, allowing attackers to read or modify data, install backdoors, or use the server as a pivot.
Affected Systems
The affected product is the Joomla Event Manager (JEM) extension distributed by joomlaeventmanager.net. Versions prior to 5.0.1 are vulnerable. The extension targets Joomla CMS installations that have installed JEM. Administrators of Joomla sites running these versions must check their installation.
Risk and Exploitability
The CVSS base score is 9.4, indicating a critical level of risk. The EPSS score is not available, so exploitation likelihood cannot be quantified, but the presence of a direct file upload route to the admin interface suggests a straightforward attack path for users with administrator credentials. The vulnerability is not listed in CISA’s KEV catalog, implying no public exploit noted at the time of analysis. Despite the lack of an EPSS value, users with admin access should treat this as a high‑risk condition and act promptly to defend against exploitation.
OpenCVE Enrichment