Impact
A vulnerability exists in the joomgalleryfriends.net JoomGallery extension for Joomla that permits unauthenticated users to upload arbitrary files through the TUS endpoint. While the attacker's control over file name and extension is limited, the ability to inject any file into the server creates a potential vector for executing malicious code if the server is configured to run uploaded content. The flaw represents an improper access control weakness, categorized as CWE-284.
Affected Systems
All installations of the joomgalleryfriends.net JoomGallery extension for Joomla that use a version earlier than 4.4.1 are vulnerable. No further version granularity is provided; any release below 4.4.1 is considered affected until an update is applied.
Risk and Exploitability
The CVSS v3 score of 6.3 indicates medium severity. The EPSS score is < 1%, suggesting a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers can reach the vulnerable endpoint remotely; files placed in the upload directory, a condition that is uncommon in default Joomla configurations but can exist in custom deployments. Consequently, the overall risk is contingent on the server’s configuration and may rise to high if execution is permitted.
OpenCVE Enrichment