🔐 CVE Alert

CVE-2026-102427

UNKNOWN 0.0

Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s content with a real magic-byte MIME check, but the extension allow-list that would otherwise restrict the saved file’s extension was present in the source and commented out. The saved file’s extension was taken directly from the attacker-supplied filename with no validation, and the file was written to a path directly under the Joomla web root that is executed by the PHP handler. An image/PHP polyglot, a file whose header bytes satisfy the MIME check with PHP source appended after, passed the content check while carrying a .php extension of the attacker’s choosing.

CWE CWE-434
Vendor ordasoft.com
Product ordasoft joomla cck
Published Sep 30, 2026
Last Updated Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for ordasoft.com ordasoft joomla cck

Be the first to know when new unknown vulnerabilities affecting ordasoft.com ordasoft joomla cck are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

ordasoft.com / OrdaSoft Joomla CCK
1.0.0-8.3.15

References

NVD ↗ CVE.org ↗ EPSS Data ↗
ordasoft.com: https://www.ordasoft.com/

Credits

Ala Arfaoui