Опубликовано: 20 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 10
CVSS3: 9.8
Описание
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2026-48939
- https://github.com/Polosss/By-Poloss..-..CVE-2026-48939
- https://mysites.guru/blog/icagenda-zero-day-file-upload-rce
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48939
- https://www.icagenda.com
- https://www.icagenda.com/docs/changelog/icagenda-3-9-15
- https://www.icagenda.com/docs/changelog/icagenda-4-0-8
EPSS
Процентиль: 97%
0.19727
Средний
10 Critical
CVSS4
9.8 Critical
CVSS3
CVE ID
Дефекты
CWE-284
CWE-434
Связанные уязвимости
CVSS3: 9.8
nvd
3 месяца назад
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
EPSS
Процентиль: 97%
0.19727
Средний
10 Critical
CVSS4
9.8 Critical
CVSS3
CVE ID
Дефекты
CWE-284
CWE-434