CVE-2026-49049
The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and upda…
HIGH
helix3
Plugin
Source officielle
Description
The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.
Sévérité
7.5
Élevée · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Score retenu : NVD
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| NVD | HIGH | 7.5 (v3.1) |
Produit et versions
- Produit
- helix3
- Type
- Plugin
- Corrigée dans
- Non précisée
- Publiée
- 29/06/2026
- Modifiée
- 30/06/2026
- CWE
- CWE-284
Versions concernées
- Helix3 extension for Joomla — 1.0 – 3.1.1
- helix3 — 1.0 – 3.1.1
Sources
- NVD CNA Joomla CVE-2026-49049 vu
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Détectée via nvd26/09/2026 09:34 UTC