All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-67284
MEDIUMpublished 2026-08-12 10:17 UTC · 17 hours ago · modified 2026-08-12 13:17 UTC
5.3
CVSS / 10
// description
Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 - Authenticated users could perform various file-related operations (read, delete, overwrite, re-assign permissions) on files owned by other users.
// weaknesses (CWE)
- CWE-284