Impact
A vulnerability in the AcyMailing Enterprise extension for Joomla allows an attacker to delete any file on the server without authentication. By storing a file path in a custom field and subsequently clearing that field, the extension will delete the referenced file, including files outside the intended upload directory such as configuration.php. This flaw can result in the loss of critical system files, potential interruption of site functionality, and unauthorized modification of site configuration. The weakness maps to the input validation flaw identified by CWE-89, where unsanitized input is used to determine deletion targets.
Affected Systems
The issue affects the acymailing.com AcyMailing Enterprise extension for Joomla on all versions earlier than 11.1.0. The extension continues to allow arbitrary file deletion until a patch is applied. No specific sub‑versions are listed, so all installations running < 11.1.0 are considered vulnerable.
Risk and Exploitability
The CVSS score of 8.3 indicates a high severity vulnerability. Because the exploit is unauthenticated and requires only the ability to submit a form that clears a custom field, a malicious actor could remotely trigger the file deletion without logging in. While an EPSS score is not available, the lack of an established KEV listing suggests no publicly known exploitation yet. Nevertheless, the potential for critical file removal warrants immediate remediation. Administrators should treat this flaw as a high‑risk threat until the patch is applied.
OpenCVE Enrichment