OrdaSoft Joomla CCK Unauthenticated Remote Code Execution Vulnerability
Worried this affects your website?
OrdaSoft Joomla CCK versions before 8.3.16 contain an unauthenticated remote code execution vulnerability. The component's site/uploader.php is reachable through normal frontend routing via task=getContent, with no authentication or ACL check in the dispatch chain.
The upload handler performs a real magic-byte MIME check on file content, but the extension allow-list that would restrict saved file extensions is commented out in the source. The saved extension is taken directly from the attacker-supplied filename without validation, and the file is written to a path under the Joomla web root that the PHP handler executes.
- Affected: OrdaSoft Joomla CCK before 8.3.16
- Attack vector: unauthenticated frontend request to task=getContent
- Impact: arbitrary PHP file upload and remote code execution
An image/PHP polyglot—a file whose header bytes satisfy the MIME check with PHP source appended—can pass the content check while carrying a .php extension of the attacker's choosing.
Reference: CVE-2026-102427 on NVD
← Back to Security News