CVE-2025-48907
MEDIUMHarmonyOS - Denial of Service via IPC Module Deserialization
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-48907. PoCs published by 0xgh057r3c0n.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-48907, targeting an unauthenticated file upload vulnerability in Joomla! JCE extension versions below 2.9.99.5. The exploit demonstrates remote code execution by uploading arbitrary PHP files via a CSRF-protected endpoint, bypassing authentication.
Description
Deserialization vulnerability in the IPC module Impact: Successful exploitation of this vulnerability may affect availability.
Exploits (1)
This repository contains a functional exploit for CVE-2026-48907, targeting an unauthenticated file upload vulnerability in Joomla! JCE extension versions below 2.9.99.5. The exploit demonstrates remote code execution by uploading arbitrary PHP files via a CSRF-protected endpoint, bypassing authentication.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H