Executive brief
A vulnerability in the K2 content management extension for Joomla allows users with 'Author' permissions to upload malicious files. By uploading a PHP script as an article attachment, an attacker can gain full control over the web server. This could lead to the theft of sensitive data, website defacement, or a complete service outage.
Technical details
An unrestricted file upload vulnerability (CWE-434) exists in the K2 frontend article-attachment upload path. The application fails to validate or sanitize file extensions, allowing files with a `.php` extension to be uploaded to the `/media/k2/attachments/` directory. Because standard Apache mod_php configurations execute files ending in `.php`, an authenticated user with 'Author' privileges can upload a web shell and execute arbitrary PHP code in the context of the web server user. The vulnerability affects K2 versions 1.0 through 2.26.
Affected products
- getk2.com K2 extension for Joomla 1.0-2.26
Timeline
- 2026-06-25: disclosed: CVE published by Joomla! Project