Executive brief
OrdaSoft Joomla Gallery is a media management extension for Joomla websites. The extension's watermark feature fails to validate uploaded file types, allowing authenticated administrators to upload and execute PHP code by masquerading files with fake image headers. An attacker with admin privileges can gain complete control over the Joomla website and its server.
Technical details
The saveWatermark() function in OrdaSoft Joomla Gallery accepts file uploads without extension validation, content-type checking, or filename sanitization, storing them in a web-accessible directory. An authenticated user with core.manage privileges can upload a PHP file with a spoofed image Content-Type header, then directly execute it via HTTP request. This is a post-authentication arbitrary file upload leading to remote code execution.
Affected products
- OrdaSoft Joomla Gallery < 6.2.7
Timeline
- 2026-09-20: disclosed