Impact
The vulnerability arises when the AcyMailing Enterprise extension for Joomla, version numbers earlier than 11.1.0, accepts incoming emails and writes each MIME part directly to the media/com_acym/upload/ directory without validating file extensions. This flaw lets an attacker who can send mail to the monitored inbox write a PHP file into the webroot, effectively executing arbitrary server‑side code.
Affected Systems
AcyMailing Enterprise extension for Joomla hosted by acymailing.com, versions prior to 11.1.0. No other products are affected; the issue is limited to the mailbox action feature of this extension.
Risk and Exploitability
The CVSS score of 9.5 indicates a critical impact, and the EPSS score is not available. The flaw is not listed in the CISA KEV catalog, but the lack of an EPSS figure does not diminish the likelihood of exploitation. An attacker can trigger the vulnerability by simply sending a specially crafted email to the monitored mailbox, bypassing authentication and enabling remote code execution.
OpenCVE Enrichment