loader image
Engineer touches holographic network with red cracks symbolizing Joomla flaw; server racks and city skyline behind.
Joomla Framework Flaw Lets Attackers Hijack Sites

Critical security vulnerabilities have been discovered in the Joomla framework, specifically in the Novarain/Tassos Framework, exposing websites to significant threats like SQL injection and unauthorized file access. These flaws, located within multiple popular extensions such as Convert Forms and EngageBox, can lead to remote code execution if left unpatched.

Security researchers identified three core weaknesses in the framework’s source code. By manipulating the AJAX handler, attackers can exploit PHP classes, access arbitrary files, and perform unauthorized deletions. One of the classes mishandles CSV data, while another facilitates unauthorized file removal. Furthermore, the dynamic field population feature could lead to SQL injection, allowing attackers to access sensitive database information.

The vendor has released updated builds to address these issues and advises immediate patching. Administrators must update or disable these components and implement additional security measures to mitigate risks.

Read the full article for more details on safeguarding your website against these vulnerabilities:

Joomla Novarain/Tassos Framework Vulnerabilities Enables SQL injection and Unauthenticated File Read

Write a Reply or Comment

Your email address will not be published. Required fields are marked *