[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":44,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":51,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":57,"vulnerability-29734":64},[4,15,21,27,33,39],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Network Scanner","compliance-pages-launch-network-scanner","Scheduled scans are the spine of every compliance framework. Are you audit-ready?","https:\u002F\u002Fpentest-tools.com\u002Fusage\u002Fcompliance",false,[11],"\u002Fnetwork-vulnerability-scanning\u002Fnetwork-security-scanner-online","Get compliance evidence","secondary","compliance-pages-launch",{"title":16,"slug":17,"text":18,"link":8,"external":9,"targets":19,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Website Scanner","compliance-pages-launch-website-scanner","Authenticated web-app scans show up in SOC 2, NIS2, and CRA Annex I. See why this is crucial for the business.",[20],"\u002Fwebsite-vulnerability-scanning\u002Fwebsite-scanner",{"title":22,"slug":23,"text":24,"link":8,"external":9,"targets":25,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Advanced Pentest Reporting","compliance-pages-launch-reporting","Editable DOCX. Immutable PDF. JSON for the GRC tool. See why these formats are on every auditor's checklist.",[26],"\u002Ffeatures\u002Fpentest-reporting",{"title":28,"slug":29,"text":30,"link":8,"external":9,"targets":31,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Integrations","compliance-pages-launch-integrations","Vanta, Jira, webhooks - they all route back to DORA, NIS2, SOC 2, ISO 27001, CRA. See why this is crucial for the business.",[32],"\u002Ffeatures\u002Fintegrations",{"title":34,"slug":35,"text":36,"link":8,"external":9,"targets":37,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Sniper","compliance-pages-launch-sniper","Five compliance framework pages now reference Sniper as the source of validated exploitability evidence. See them all.",[38],"\u002Fexploit-helpers\u002Fsniper",{"title":40,"slug":14,"text":41,"link":8,"external":9,"targets":42,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Homepage","Turn confirmed vulnerabilities into evidence your auditor accepts. Testing requirements for DORA, NIS2, SOC 2, ISO 27001, and CRA.",[43],"\u002F",["Island",45],{"key":46,"params":47,"result":49},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":48},"{}",{"head":50},{},["Island",52],{"key":53,"params":54,"result":55},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":48},{"head":56},{},["Island",58],{"key":59,"params":60,"result":62},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":61},"{\"text-color\":\"gray\"}",{"head":63},{},{"id":65,"detectable_with":66,"vuln_details":72,"vuln_id":94,"name":95,"published":96,"updated":96},29734,{"tool":67,"engine":70},{"id":68,"name":69},1,"Network Scanner",{"id":68,"name":71},"Sniper",{"id":65,"codename":73,"description":74,"severity":75,"risk_description":76,"public_description":77,"public_recommendation":78,"recommendation":79,"references":80,"cvssv3":83,"epss_score":84,"epss_percentile":85,"cve":86,"in_cisa_catalog":88,"date":89,"software_type":90,"vendor":91,"product":91,"ptt_exploit_capabilities":92},null,"We found that the target Joomla site is running the iCagenda extension, versions 3.2.1 to 3.9.14 and 4.0.0 to 4.0.7, which is vulnerable to an unauthenticated remote code execution. The vulnerability stems from a missing access check in the event registration controller (com_icagenda, task=submit.submit): the front-end 'Submit Event' view is access-gated, but the controller it posts to performs no such check, only CSRF validation. An unauthenticated attacker can submit a crafted multipart\u002Fform-data request directly to the controller, attaching a PHP file as the event's attachment. The file is stored under the web-accessible images\u002Ficagenda\u002Ffrontend\u002Fattachments\u002F directory without content or extension validation, letting the attacker execute arbitrary code by requesting the uploaded file directly.","critical","Successful exploitation allows remote code execution as the web server user, enabling full server compromise including data exfiltration, deployment of malware or ransomware, and lateral movement within the internal network. The vulnerability is high severity and likely to be exploited in the wild because it requires no authentication and proof-of-concept exploit code is publicly available.","The iCagenda extension for Joomla, versions 3.2.1 to 3.9.14 and 4.0.0 to 4.0.7, is vulnerable to unauthenticated remote code execution due to an unrestricted file upload in its event registration feature. An attacker can submit a crafted multipart\u002Fform-data request directly to the registration controller (com_icagenda, task=submit.submit), bypassing the access-gated submission view, and attach a PHP file as the event's attachment. Because the endpoint requires no authentication and performs insufficient validation, the uploaded PHP file is stored under a web-accessible directory and can be requested and executed remotely.","Update the iCagenda extension to version 3.9.15 (3.x branch) or 4.0.8 (4.x branch) or later.","We recommend updating the iCagenda extension to version 3.9.15 (3.x branch) or 4.0.8 (4.x branch) or later; if immediate update is not possible, disable or restrict the event registration\u002Fattachment feature and ensure uploaded files are stored outside a web-executable location.",[81,82],"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-48939","https:\u002F\u002Fgithub.com\u002FChiefYoru\u002FCVE-2026-48939_PoC",9.8,0.20069,0.97379,[87],"CVE-2026-48939",true,"2026-06-20T00:00:00Z","Joomla Extension","iCagenda",[93],"RCE","NETSCAN-SNIPER-CVE-2026-48939","Joomla iCagenda - Remote Code Execution","2026-09-07T00:00:00Z"]