Critical CVSS 9.2

Overview

An authenticated RCE vulnerability in Phoca Commander component 1.0.0-4.0.0 and 5.0.0-5.0.1 for Joomla was discovered. The issue allows code execution via the unzip feature.

Risk analysis

This vulnerability is rated 🔴 CRITICAL.

  • CVSS: 9.2 (CRITICAL)
  • Detected tags: joomla, rce (tag impact: VERY HIGH)

Recommended actions:

  • Patch/upgrade immediately (remote code execution).
  • Reduce exposure (WAF/segmentation), minimize attack surface.

Recommended tools

Tags