Description
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
CVSS breakdown
CVSS 4.0
Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Confidentiality (Vulnerable System)
High
Integrity (Vulnerable System)
High
Availability (Vulnerable System)
High
Confidentiality (Subsequent System)
High
Integrity (Subsequent System)
High
Availability (Subsequent System)
High
E
Adjacent
AU
Y
U
Red
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- joomlack / page_builder_ck3.6.0
- joomlack.fr / JoomlaCK.fr Page Builder CK extension for Joomla1.0-3.6.0 – 1.0-3.6.0
Exploits & proofs of concept
- exploit-dbJoomla Page Builder CK 3.5.10 - Arbitrary File Uploadby M@rAz Ali
- nucleiPage Builder CK <= 3.5.10 - Unauthenticated Arbitrary File Uploadby panchiko-p,0x_Akoko
References
Updated 14m ago · 8 sources