Joomla Extension - phoca.cz - Authenticated file upload in Phoca Downloads component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.
References
| Link | Resource |
|---|---|
| https://mysites.guru/blog/phoca-download-authenticated-file-upload-rce/ | Exploit Third Party Advisory |
| https://www.phoca.cz/phocadownload | Product |
Configurations
History
No history.
Information
Published : 2026-07-11 10:16
Updated : 2026-08-19 15:17
NVD link : CVE-2026-57828
Mitre link : CVE-2026-57828
CVE.ORG link : CVE-2026-57828
JSON object : View
Products Affected
phoca
- download
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
