Executive brief
ThemeXpert JMedia, a media management extension for the Joomla content management system, contains a security vulnerability that allows authorized users to upload malicious files. By exploiting this flaw, an attacker with administrative access could upload executable scripts to the server, potentially leading to a full takeover of the website and its underlying data. This could result in complete service disruption, data theft, or the installation of ransomware.
Technical details
ThemeXpert JMedia versions 1.0 through 1.5.4 suffer from an unrestricted file upload vulnerability (CWE-434). The extension fails to properly validate uploaded files, allowing for the upload of executable scripts, including those using polyglot filenames to bypass filters. Additionally, the application's permission management (chmod) fails to strip execute bits from uploaded files. An authenticated attacker with high privileges (PR:H) can leverage this to upload and execute arbitrary PHP code on the server, resulting in full system compromise. The vulnerability is reachable over the network without user interaction.
Affected products
- ThemeXpert JMedia extension for Joomla 1.0-1.5.4
Timeline
- 2026-07-20: advisory: CVE-2026-60032 published by the Joomla! Project