A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://www.icagenda.com/ |
Configurations
No configuration.
History
20 Jun 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-20 13:16
Updated : 2026-06-22 19:17
NVD link : CVE-2026-48939
Mitre link : CVE-2026-48939
CVE.ORG link : CVE-2026-48939
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control
