CyberRota Analysis
AI-GeneratedThe Phoca Commander extension for Joomla is vulnerable to arbitrary file read due to improper path restrictions in the getSource function, allowing attackers to access sensitive files on the server. This high-severity vulnerability could lead to data exposure and compromise the integrity of the affected systems. Joomla administrators and developers using this extension should prioritize immediate remediation to mitigate potential risks.
CVE
CVE-2026-66491
Severity
HIGH
CVSS
8.2
EPSS
0.31%
Original NVD Description
Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the getSource function lead to an arbitrary file read vulnerability.