Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-48944

Опубликовано: 25 июн. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

The K2 frontend article-save handler accepts an attachment[N][existing] POST field that is concatenated with JPATH_SITE/ and passed to JFile::copy(). JPath::clean does NOT strip .., and there is no allow-list of source paths. An Author can therefore copy configuration.php (or any other file readable by the web user — including ../../../etc/passwd) into /media/k2/attachments/, then retrieve the contents via the K2 attachment-download endpoint.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:joomlaworks:k2:*:*:*:*:*:joomla\!:*:*
Версия до 2.26 (включая)

EPSS

Процентиль: 22%
0.00295
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.5
github
2 месяца назад

The K2 frontend article-save handler accepts an `attachment[N][existing]` POST field that is concatenated with `JPATH_SITE/` and passed to `JFile::copy()`. `JPath::clean` does NOT strip `..`, and there is no allow-list of source paths. An Author can therefore copy `configuration.php` (or any other file readable by the web user — including `../../../etc/passwd`) into `/media/k2/attachments/`, then retrieve the contents via the K2 attachment-download endpoint.

EPSS

Процентиль: 22%
0.00295
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22