CVE-2026-65891

Vulnérabilités

CVE-2026-65891

Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.20.2

MEDIUM jce Source officielle

Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.20.2 - Improper input validation in the file rename functionality allowed an authenticated user with file management permissions to rename files to otherwise invalid names, resulting in the creation of hidden files. The issue also allowed existing files at the destination path to be unintentionally replaced.

6.5 Moyenne · CVSS 3.1

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Score retenu : NVD

SourceSévérité d'origineCVSS
NVDMEDIUM 6.5 (v3.1)
Produit
jce
Corrigée dans
2.20.2
Publiée
29/07/2026
Modifiée
05/08/2026
CWE
CWE-20
  • Joomla Content Editor (JCE) extension for Joomla — 1.0.0 – 2.9.99.9
  • jce — jusqu'à 2.20.2 (exclue)

Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.

  1. Détectée via nvd26/09/2026 09:34 UTC