Impact
The TUS endpoint of the joomgalleryfriends.net JoomGallery extension for Joomla accepts arbitrary file uploads from unauthenticated users. Although the attacker cannot control the file name or its extension, any file type can be uploaded. Execution of uploaded code requires that the server is configured in a non‑standard way that allows running uploaded content, which is not typical for default Joomla deployments. The vulnerability is an improper access control weakness, corresponding to CWE‑284.
Affected Systems
All installations of the joomgalleryfriends.net JoomGallery extension for Joomla that use a version earlier than 4.4.2 are vulnerable. No further version granularity is provided; any release below 4.4.2 is considered affected until an update is applied.
Risk and Exploitability
The CVSS v3 score of 6.3 indicates medium severity. The EPSS score is < 1%, suggesting a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers can reach the vulnerable endpoint remotely; files placed in the upload directory, a condition that is uncommon in default Joomla configurations but can exist in custom deployments. Consequently, the overall risk is contingent on the server’s configuration and may rise to high if execution is permitted.
OpenCVE Enrichment