CISA Warns of Actively Exploited RCE Flaws in Joomla Extensions
ID: 9ed7b763-796e-5dec-9c29-8d78c2e5faea
STIX ID: report--9ed7b763-796e-5dec-9c29-8d78c2e5faea
Feed Name: CosmicBytez Labs
**CISA added two critical arbitrary file upload vulnerabilities in Joomla extensions (iCagenda and Balbooa Forms) to its Known Exploited Vulnerabilities list, warning that attackers are actively exploiting these flaws to upload webshells and achieve remote code execution on affected web servers; the report outlines exploitation steps, affected environments, detection indicators (unexpected PHP uploads, log patterns, outbound connections), and remediation actions including patching, auditing uploads, and restricting upload functionality.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
