CyberRota Analysis
AI-GeneratedThe Sourcerer extension for Joomla is vulnerable due to multiple code injection vectors that allow unauthorized execution of PHP code without proper user permissions. This critical vulnerability can lead to arbitrary code execution, potentially compromising the integrity and security of affected systems. Organizations using the Sourcerer extension, particularly those managing sensitive data or critical applications, should prioritize immediate remediation to mitigate the risk of exploitation.
Original NVD Description
Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection.