Impact
The vulnerability resides in the OrdaSoft Joomla Gallery extension for Joomla. An authenticated user with sufficient privileges can instruct the extension to execute an arbitrary PHP function by sending a specially crafted JSON payload to the updateOSGallery task. Because the extension directly interprets the value of a method field as a live PHP function without any allow‑list or is_callable() check, functions such as system, exec, shell_exec, and passthru can be invoked. This flaw provides remote code execution on the web server, allowing an attacker to compromise the host, install malware, exfiltrate data, or pivot to other systems. The weakness is a classic example of code injection, mapped to CWE‑94.
Affected Systems
The flaw affects the OrdaSoft Joomla Gallery extension (both paid and free variants) for Joomla versions earlier than 6.2.7. Attackers must be able to authenticate to the Joomla site and possess privileged access to invoke the updateOSGallery task. No other vendors or product families are cited as impacted.
Risk and Exploitability
The CVSS score of 9.4 indicates delivery, installation, execution, and exfiltration capabilities are all satisfied, and the flaw is exploitable locally in the context of the web application. The EPSS score is not available, but the absence of a listing in the CISA KEV catalog does not diminish the severity of the flaw. The likely attack vector is through a normal Joomla session with administrative privileges enabling the updateOSGallery task. The lack of any additional verification or function whitelisting makes exploitation straightforward for a knowledgeable attacker.
OpenCVE Enrichment