SecureController@upload of the file /uploads/upload of the component Helper. The manipulation of the argument restricted_extensions results in unrestricted upload.
This vulnerability is reported as CVE-2026-53593. The attack can be launched remotely. No exploit exists.
Intelligence View
SOCIAL SHARE CARD GENERATOR