CVE-2026-48943

Vulnérabilités

CVE-2026-48943

K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`.

MEDIUM k2 Plugin Source officielle

K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. A Registered Joomla user, by including the field `K2UserForm=1` in a standard `com_users` `profile.save` POST, can write arbitrary values into the `notes`, `image`, and `plugins` columns of their own row in the `#__k2_users` table — none of which are exposed by the K2 frontend profile-edit form.

6.5 Moyenne · CVSS 3.1

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Score retenu : NVD

SourceSévérité d'origineCVSS
NVDMEDIUM 6.5 (v3.1)
Produit
k2
Type
Plugin
Corrigée dans
Non précisée
Publiée
25/06/2026
Modifiée
28/06/2026
CWE
CWE-915
  • K2 extension for Joomla — 1.0 – 2.26
  • k2 — jusqu'à 2.26

Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.

  1. Détectée via nvd26/09/2026 09:34 UTC