logo

Joomla Novarain/Tassos Framework Vulnerabilities Enables SQL injection and Unauthenticated File Read

ID: a669256d-ce03-5041-b40b-3af2896a0a78

STIX ID: report--a669256d-ce03-5041-b40b-3af2896a0a78

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-02-16

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical vulnerability in the Novarain/Tassos Framework plugin (plg_system_nrframework), bundled into several popular Joomla extensions, exposes an unauthenticated AJAX entry (task=include) that can be abused for arbitrary file reads, file deletions, and SQL injection; chaining these primitives can yield administrator session theft, backend access, and persistent remote code execution. Administrators are advised to immediately apply vendor patches, disable the plugin temporarily if exposed, and monitor/compress com_ajax traffic and logs for suspicious include requests or unexpected file operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.