
Python CLI that exploits CVE-2026-48907 in Joomla JCE via profile-import upload, verifies shell paths, and opens an interactive command channel on authorized targets.
E.L.V — Exploit Loader & Vulnerability Firmware
Cybersecurity research utility for authorized vulnerability assessment.
E.L.V CVE Research & Assessment Framework is a Python-based command-line utility intended for controlled security research and authorized vulnerability assessment.
The supplied implementation contains functionality for:
The current source identifies its research target as:
CVE-2026-48907 Joomla! JCE Extension < 2.9.99.5 Unauthenticated RCE
That CVE/product claim is metadata supplied by the source code and has not been independently verified by this README. Before publishing a security claim, validate the identifier, affected versions, advisory, affected component, and remediation information against a trusted vendor/CVE source.
This project interacts with remote web applications and the supplied implementation includes functionality intended to upload a custom server-side payload and communicate with an uploaded shell.
Use it only against systems for which you have explicit authorization.
Do not use this project to:
For a safe laboratory, use an isolated local VM/container environment or a deliberately vulnerable training target.
| Field | Value |
|---|---|
| Project | E.L.V CVE Research & Assessment Framework |
| Author / Engine | HxN / E.L.V |
| Version | 1.0.0 |
| Language | Python |
| Platform | *nix / Unix-like systems |
| License | GNU GPL v3 |
| Interface | Command line |
| HTTP Client | requests |
| Concurrency | ThreadPoolExecutor |
| Primary Purpose | Authorized security research and assessment |
The supplied elv-cve.py source contains the following major components.
The script reads a local file supplied through the --shell option.
The source describes this as a custom shell/uploader file and terminates when the specified file cannot be read.
The program supports two mutually exclusive target modes:
For each target, the script performs a GET request against the target root and expects an HTTP 200 response before continuing.
The implementation searches the returned HTML for a CSRF-related value using regular expressions.
Two patterns are currently implemented.
The script constructs a multipart upload request against:
/index.php?option=com_jce
The request includes the profile-import task and the extracted token.
After the upload request, the program checks several possible locations for the resulting file.
The current source contains these candidate paths:
/tmp/
/images/
/images/stories/
/media/
For a single target, the current program invokes an interactive command interface when it reports a successful uploaded shell path.
The source sends commands using POST parameters named:
cmd
c
Because this functionality can result in remote command execution, it should be restricted to isolated, explicitly authorized environments.
When a target file is supplied, the program uses a ThreadPoolExecutor and processes targets concurrently.
The default thread count in the source is:
10
At a high level, the current implementation follows this flow:
Start
│
├── Parse command-line arguments
│
├── Load local payload file
│
├── Load one target OR target list
│
├── Create ELV_CVE output directory
│
├── Target processing
│ │
│ ├── GET target
│ ├── Check HTTP response
│ ├── Extract token
│ ├── Submit profile-import request
│ ├── Check candidate file paths
│ └── Record result
│
└── Write results / display summary
The supplied source imports:
randomretimeargparsesysosjsonthreadingconcurrent.futuresrequestsurllib3A minimal dependency installation is therefore:
python3 -m pip install requests urllib3
For reproducible deployments, pin dependencies in a requirements.txt file.
Example:
requests
urllib3
Clone or copy the project into an isolated assessment environment.
Example:
git clone <YOUR-REPOSITORY-URL>
cd <YOUR-REPOSITORY-DIRECTORY>
Create a virtual environment:
python3 -m venv .venv
Activate it:
source .venv/bin/activate
Install dependencies:
python3 -m pip install -r requirements.txt
Verify Python:
python3 --version
Verify the dependency:
python3 -c "import requests, urllib3; print('Dependencies OK')"
Replace
<YOUR-REPOSITORY-URL>and<YOUR-REPOSITORY-DIRECTORY>with the values used by your repository.
The source defines the following command-line options.
-u, --url
Single target URL.
-f, --file
Path to a file containing target URLs.
These options are mutually exclusive and one of them is required.
--shell
Path to the local custom payload file.
This argument is required by the current implementation.
-t, --threads
Number of worker threads.
Default:
10
-v, --verbose
Enables the verbose flag exposed by the argument parser.