Back to overview

CVE-2026-48946

MEDIUM
6.3
CVSS 3.1
Description
The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php matches `\.php$` and executes them under the K2 web user. A K2 Author can upload a `shell.php`, then fetch `/media/k2/attachments/shell.php` and execute arbitrary PHP code in the web server's context.

Metadata

CVE ID
CVE-2026-48946
State
PUBLISHED
Assigner
Joomla
Reserved
2026-05-26 16:47 UTC
Published
2026-06-25 15:25 UTC
Last updated
2026-06-25 18:52 UTC
Primary CWE
CWE-434
CWE-434 Unrestricted Upload of File with Dangerous Type
Vendor / Product
getk2.com / K2 extension for Joomla
Sources
cve.org  ·  NVD

Severity & Metrics

6.3 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
getk2.com K2 extension for Joomla 1.0-2.26
Weakness (CWE)
CWESourceDescription
CWE-434 cna CWE-434 Unrestricted Upload of File with Dangerous Type
CVSS scores (1)
ScoreSeverityVersionSourceVector
6.3 MEDIUM 3.1 adp CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
References (1)
Back to overview