Impact
The vulnerability allows an unauthenticated attacker to install arbitrary code through the UP plugin in Joomla, effectively giving full control over the compromised site. It is a path traversal and access control issue that enables the attacker to create or replace files and execute them, leading to full system compromise, data exfiltration, and service disruption.
Affected Systems
The issue affects the lomart.fr UP plugin for Joomla. Vulnerable plugin versions include 5.0.0 through 5.2.0 and 6.0.0 through 6.0.29. Organizations using these versions should assess their installations immediately.
Risk and Exploitability
The CVSS score of 10 indicates critical severity. Although EPSS data is not available, the lack of a KEV listing does not decrease the urgency; the flaw remains exploitable without authentication. The likely attack vector involves sending crafted requests to the plugin’s endpoint, allowing the attacker to place malicious files on the server. Given the critical score, the potential impact is high and rapid exploitation is plausible whenever the plugin is exposed to the web.
OpenCVE Enrichment