Impact
The OrdaSoft Joomla Gallery extension copies an uploaded file into a web‑accessible directory without checking the file extension, verifying content, or sanitizing the file name. An attacker who is an authenticated core.manage user can therefore upload a PHP file disguised with an image Content‑Type header and later execute it by accessing the resulting URL. This flaw allows full remote code execution on the affected system, compromising confidentiality, integrity, and availability.
Affected Systems
The vulnerability is confined to OrdaSoft.com’s Joomla Gallery extension for Joomla, in both the paid and free variants. All releases older than version 6.2.7 are affected. Exploitation requires an authenticated account with core.manage privileges, so the impact is limited to sites that grant such rights to users who should not be able to upload arbitrary files.
Risk and Exploitability
The CVSS score of 9.4 categorises the issue as critical. Although the EPSS score is not available, the absence of any file‑type or content validation, coupled with the ability to write files to a public directory, means attacks could be launched with little effort. The vulnerability is not yet listed in CISA’s KEV catalog, but the potential for widespread exploitation remains high.
OpenCVE Enrichment