National Cyber Warfare Foundation (NCWF)

CVE-2026-48943


0 user ratings
2026-05-26 00:00:00
milo
CVEs

 - archive -- 

CVE-2026-48943

Date: 2026-05-26

CVE Link

K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. A Registered Joomla user, by including the field `K2UserForm=1` in a standard `com_users` `profile.save` POST, can write arbitrary values into the `notes`, `image`, and `plugins` columns of their own row in the `#__k2_users` table — none of which are exposed by the K2 frontend profile-edit form.



References:



Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
CVEs



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.