Impact
The flaw is an authenticated, privileged PHP command injection in the UP plugin for Joomla hosted by lomart.fr. An attacker who can log in with sufficient privileges can supply crafted input that is executed by the server as a shell command. This allows arbitrary code execution on the web server using the Joomla approval level, potentially giving full control over the site, uploading malicious files, and exfiltrating data. The weakness is identified as CWE‑94.
Affected Systems
The vulnerable component is the UP plugin for Joomla provided by lomart.fr. Versions 5.0.0 through 5.2.0 and 6.0.0 through 6.0.29 are affected. Sites using those plugin releases should assume the vulnerability exists unless it has been updated to a later, non‑vulnerable version.
Risk and Exploitability
The CVSS base score of 9.4 marks this as Critical. Although the EPSS score is not available, the lack of a KEV listing suggests no widespread public exploits yet. However, an attacker already possessing Joomla credentials can exploit the flaw, and the command injection grants full server access. The high severity combined with the requirement for authenticated access creates a significant risk for sites with compromised or weak user accounts.
OpenCVE Enrichment