All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-67283
MEDIUMpublished 2026-08-12 09:17 UTC · 18 hours ago · modified 2026-08-12 13:17 UTC
6.9
CVSS / 10
// description
Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenticated users could perform various file-related operations (read, delete, overwrite, re-assign permissions) on every file managed within the extension.
// weaknesses (CWE)
- CWE-284