CyberRota Analysis
AI-GeneratedThe J-BusinessDirectory extension for Joomla versions prior to 6.2.3 is vulnerable to arbitrary file upload and deletion due to inadequate path containment and weak extension validation, allowing attackers to manipulate file paths. This critical vulnerability, compounded by the absence of a CSRF token, could lead to unauthorized access and potential compromise of the web server. Organizations using this extension should prioritize immediate updates to mitigate the risk of exploitation.
Original NVD Description
Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path containment, and used a weak extension check. CSRF token was also missing on upload/remove.