Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.ordasoft.com/ |
|
Thu, 01 Oct 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ordasoft.com
Ordasoft.com ordasoft Joomla Cck |
|
| Vendors & Products |
Ordasoft.com
Ordasoft.com ordasoft Joomla Cck |
Thu, 01 Oct 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ordasoft
Ordasoft joomla Cck |
|
| CPEs | cpe:2.3:a:ordasoft:joomla_cck:*:*:*:*:*:joomla\!:*:* | |
| Vendors & Products |
Ordasoft
Ordasoft joomla Cck |
|
| Metrics |
cvssV3_1
|
Wed, 30 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s content with a real magic-byte MIME check, but the extension allow-list that would otherwise restrict the saved file’s extension was present in the source and commented out. The saved file’s extension was taken directly from the attacker-supplied filename with no validation, and the file was written to a path directly under the Joomla web root that is executed by the PHP handler. An image/PHP polyglot, a file whose header bytes satisfy the MIME check with PHP source appended after, passed the content check while carrying a .php extension of the attacker’s choosing. | |
| Title | Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Joomla
Published:
Updated: 2026-09-30T16:09:54.660Z
Reserved: 2026-09-29T04:38:08.434Z
Link: CVE-2026-102427
No data.
Status : Analyzed
Published: 2026-09-30T16:17:06.623
Modified: 2026-10-01T13:46:23.090
Link: CVE-2026-102427
No data.
OpenCVE Enrichment
Updated: 2026-10-01T15:38:57Z
-
CWE-434
Unrestricted Upload of File with Dangerous Type