← Back

CVE-2026-49049

nvd nist
Published: Jun 29, 2026Modified: Jun 30, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.

Affected (1)

Products: Ollyo: Helix3
1 product
Helix3
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 1.0 to 3.1.1

References (1)

Source: security@joomla.org
Product

Timeline

No history available yet.