Joomla 扩展 - OrdaSoft.com - OrdaSoft Joomla Gallery 扩展(适用于 Joomla < 6.2.7)中的已认证特权远程代码执行漏洞 - 该扩展的 函数在将上传文件复制到 Web 可访问目录时,直接使用了客户端提供的原始文件名,未进行任何扩展名校验、内容检查或文件名净化处理。已认证的 权限用户可上传伪装为图像 Content-Type 头的 .php 文件,并通过请求生成的路径直接执行该文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OrdaSoft.com | OrdaSoft Joomla Gallery extension for Joomla | 1.0.0-6.2.6 |
affected |
| OrdaSoft.com | OrdaSoft Joomla Gallery free extension for Joomla | 1.0.0-6.2.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OrdaSoft.com | OrdaSoft Joomla Gallery free extension for Joomla | 1.0.0-6.2.6 | - |
|
| OrdaSoft.com | OrdaSoft Joomla Gallery extension for Joomla | 1.0.0-6.2.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88856 | 9.4 CRITICAL | Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaS |
| CVE-2026-88854 | 9.3 CRITICAL | Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery |
| CVE-2026-88855 | 8.6 HIGH | Joomla Extension - OrdaSoft.com - Authenticated, Privileged SQL Injection in OrdaSoft Joom |
No comments yet