Sceawere
Vulnerability Detail
CVE-2026-102427UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated RCE in OrdaSoft CCK
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 10
- Creation Date
- 1d ago
- Vendor
- ordasoft.com
- Product
- OrdaSoft Joomla CCK
- Attack Type
- CWE-434 Unrestricted Upload of File with Dangerous Type
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s content with a real magic-byte MIME check, but the extension allow-list that would otherwise restrict the saved file’s extension was present in the source and commented out. The saved file’s extension was taken directly from the attacker-supplied filename with no validation, and the file was written to a path directly under the Joomla web root that is executed by the PHP handler. An image/PHP polyglot, a file whose header bytes satisfy the MIME check with PHP source appended after, passed the content check while carrying a .php extension of the attacker’s choosing.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "10.0",
"pubDate": "2026-09-30T16:17:06.623Z",
"pubdate": "2026-09-30T16:17:06.623Z",
"executiveSummary": "OrdaSoft Joomla CCK versions prior to 8.3.16 contain a critical Unauthenticated Remote Code Execution (RCE) vulnerability. The flaw exists within the component's file upload mechanism, which fails to enforce strict server-side validation on file extensions.\nBy leveraging an image/PHP polyglot—a file containing valid image magic bytes followed by executable PHP code—an unauthenticated remote attacker can bypass existing MIME-type checks. Because the extension allow-list is commented out in the source code, the application permits attackers to supply an arbitrary filename extension, such as .php, and write the file directly into the web root.\nThis vulnerability allows full server-side code execution, enabling an attacker to compromise the web server, access sensitive database information, or pivot within the network. Exploitation does not require prior authentication, as the vulnerable entry point is accessible through the component's frontend routing (task=getContent). Given the ease of exploitation and the potential for full system compromise, this issue carries a high-risk rating for all Joomla installations utilizing the affected OrdaSoft CCK versions.",
"technicalDetails": "The vulnerability is localized within site/uploader.php of the OrdaSoft Joomla CCK extension. The primary root cause is an insecure implementation of the file upload workflow, specifically the failure to enforce mandatory extension filtering during the write operation.\nThe attack flow begins via the component's frontend routing. By invoking task=getContent, an attacker reaches the handler without the need for authentication or Access Control List (ACL) validation. While the application attempts to perform a security check, it relies solely on a magic-byte MIME check to verify file integrity. This mechanism only ensures the uploaded content conforms to an image file structure, ignoring the actual file extension provided by the user.\nCrucially, the developer included an allow-list intended to restrict file extensions, but this logic is rendered ineffective as the code is commented out. Consequently, the application takes the attacker-supplied filename, including its extension, and writes it directly to a path within the Joomla web root. Because the server environment is configured to parse and execute files with a .php extension, the attacker can successfully upload an image/PHP polyglot.\nThe polyglot file is crafted to be dual-purpose: it maintains valid magic bytes that satisfy the MIME check, while simultaneously embedding malicious PHP payloads at the end of the file. Once written to the disk, the attacker identifies the path of the saved file and triggers execution by sending an HTTP request directly to the file location. Upon execution, the PHP interpreter ignores the non-executable image data and runs the appended malicious code with the permissions of the web server user.\nThe impact of this vulnerability is total system compromise. Following initial execution, attackers can deploy web shells, exfiltrate the configuration.php file containing database credentials, or gain a foothold for lateral movement across the hosting environment. The absence of authentication requirements makes this a highly accessible target for automated exploitation across the internet."
}