Impact
An attacker can craft file paths that traverse outside the intended directory when interacting with the UP plugin, allowing the reading of arbitrary files or the placement of executable files. The weakness is classified as CWE‑22, with inadequate access controls contributing as CWE‑284. Because the plugin is a web‑exposed extension in Joomla, the attacker can trigger these vectors over HTTP, potentially leading to confidential data exposure or code execution if a malicious file is uploaded and executed.
Affected Systems
The vulnerability affects the UP plugin for Joomla developed by lomart.fr. All releases from 5.0.0 through 5.2.0 and from 6.0.0 through 6.0.29 are impacted.
Risk and Exploitability
The CVSS score of 9.2 indicates a high‑severity flaw. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote via web requests, as the plugin processes user‑supplied input over HTTP without adequate validation. The conditions require only Web access to the plugin’s endpoints and are likely exploitable against systems that have the plugin installed with enabled file upload functionality.
OpenCVE Enrichment