CyberRota Analysis
AI-GeneratedThe Event Gallery extension for Joomla versions prior to 6.5.0 is vulnerable to authenticated arbitrary path deletion through the `clear cache` task, allowing attackers to recursively delete any directories writable by the web server using the `images` parameter. This could lead to significant data loss and disruption of service for affected Joomla installations. Web administrators and security teams managing Joomla sites with this extension should prioritize patching to mitigate potential exploitation.
Original NVD Description
Joomla Extension - svenbluege.de - Authenticated arbitrary path deletion in `clear cache` task in Event Gallery extension < 6.5.0 - Using the `images` parameter of the `cache.process` task, you can recursively delete any directories that the web server is authorized to write to.