VYPR
Unrated severityNVD Advisory· Published Jun 25, 2026· Updated Jun 28, 2026

Joomla Extension - getk2.org - Exposure of sensitive files via attachment copy in K2 extension for Joomla < 2.26

CVE-2026-48944

Description

The K2 frontend article-save handler accepts an attachment[N][existing] POST field that is concatenated with JPATH_SITE/ and passed to JFile::copy(). JPath::clean does NOT strip .., and there is no allow-list of source paths. An Author can therefore copy configuration.php (or any other file readable by the web user — including ../../../etc/passwd) into /media/k2/attachments/, then retrieve the contents via the K2 attachment-download endpoint.

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.