Joomla! Media Manager Malicious File Upload Vulnerability

Vulnerability

A vulnerability in the Joomla! Media Manager allows users with edit privileges to upload files with arbitrary extensions, including executable PHP files. This issue arises from inadequate validation of file extensions, potentially leading to the execution of malicious scripts.

Impact

Exploitation of this vulnerability allows for the upload of malicious files that could be executed on the server, potentially leading to a compromise of the web application or the underlying server.

Remediation

Users are advised to upgrade to Joomla! version 4.4.12 or 5.2.5.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.6
impact
10.0
exploitability
5.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.