CVE-2026-75949
10.0cmsjunkie.com · J-BusinessDirectory extension for Joomla
J-BusinessDirectory for Joomla contains an unauthenticated arbitrary file upload and deletion vulnerability due to path traversal and improper input validation.
Executive summary
The J-BusinessDirectory extension for Joomla is vulnerable to unauthenticated remote code execution and file manipulation, posing a critical risk to site integrity.
Vulnerability
This vulnerability allows an unauthenticated attacker to upload or delete arbitrary files by exploiting path traversal flaws in the component. The lack of CSRF protection and weak extension validation further facilitates malicious file deployment into sensitive directories.
Business impact
The ability to upload arbitrary files allows an attacker to execute malicious scripts, leading to a full system compromise. With a CVSS score of 10.0, this flaw grants attackers complete control over the web application, potentially resulting in data exfiltration, site defacement, or total loss of service.
Remediation
Immediate Action: Update the J-BusinessDirectory extension to version 6.2.3 or the latest available release immediately.
Proactive Monitoring: Review web server access logs for unusual file upload requests or unauthorized attempts to access system paths.
Compensating Controls: Implement a Web Application Firewall (WAF) rule to block requests containing directory traversal sequences or attempts to upload executable file types.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical severity and the potential for complete remote control of the Joomla environment, administrators must prioritize updating this extension. Immediate action is required to close the attack vector before it is weaponized by threat actors.