Executive brief
Phoca Commander, a file management tool for the Joomla content management system, contains a security flaw that could allow an administrator to access files outside of the intended directories. By exploiting this path traversal vulnerability, an attacker with high-level administrative privileges could download sensitive system files or save files to unauthorized locations on the server. This could lead to the exposure of confidential configuration data or disruption of website operations.
Technical details
A path traversal vulnerability (CWE-22) exists in the Phoca Commander extension for Joomla versions 1.0.0 through 6.1.1. The issue stems from improper limitation of pathnames during 'save' and 'download' operations within the file manager component. An attacker with high-level administrative privileges (PR:H) can utilize specially crafted file paths to bypass directory restrictions. This allows for the unauthorized reading of sensitive files or the writing of files to arbitrary locations on the server's filesystem, provided the web server has the necessary permissions.
Affected products
- phoca.cz Phoca Commander extension for Joomla 1.0.0-6.1.1
Timeline
- 2026-07-27: disclosed
- 2026-07-27: advisory