Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Joomla Novarain/Tassos Framework Vulnerabilities Enables SQL injection and Unauthenticated File Read

Websites utilizing the Novarain/Tassos Framework are subject to significant security vulnerabilities that enable unauthorized file reading, file deletion, and SQL injection attacks. These vulnerabilities could lead to remote code execution and complete…

Websites utilizing the Novarain/Tassos Framework are subject to significant security vulnerabilities that enable unauthorized file reading, file deletion, and SQL injection attacks. These vulnerabilities could lead to remote code execution and complete administrative control if systems remain unpatched. Immediate updates from the vendor are required to mitigate these risks.

An analysis of the Novarain/Tassos Framework plugin (plg_system_nrframework) revealed three critical vulnerabilities. These are exposed through an AJAX handler that processes the task=include action without adequate security measures.

Attackers can exploit PHP classes under the Joomla site root, leveraging the onAjax method to access internal helper classes as remotely accessible gadgets. CSV loading is improperly handled, allowing reading of arbitrary files accessible to the webserver user. A remove action is exposed, enabling deletion of attacker-supplied paths without validation. Dynamic field population passes attacker-controlled parameters into database queries, resulting in an SQL injection vulnerability.

These vulnerabilities can be chained to allow attackers to steal administrator session data, access the backend, and deploy malicious extensions or modify templates, leading to persistent remote code execution (RCE).

The framework is integrated into several popular Joomla extensions, including:

These vulnerabilities could lead to remote code execution and complete administrative control if systems remain unpatched.
Lucas Norwood · Thehackingpost

Convert Forms (v3.2.12 – v5.1.0) EngageBox (v6.0.0 – v7.1.0) Google Structured Data (v5.1.7 – v6.1.0) Advanced Custom Fields (v2.2.0 – v3.1.0) Smile Pack (v1.0.0 – v2.1.0)

The vulnerabilities affect the Novarain/Tassos Framework (plg_system_nrframework) versions v4.10.14 to v6.0.37. Exploitation is possible if the system plugin is enabled on internet-facing sites. The attack vector uses unauthenticated AJAX requests, necessitating additional security measures.

The vendor has released patched versions of the affected framework and extensions, available via the official downloads section and Joomla update mechanisms. Administrators are advised to update all Tassos components immediately or disable the plg_system_nrframework plugin and related extensions temporarily.

Advertisement

As a precaution, operators should restrict or filter com_ajax traffic at the web server or Web Application Firewall (WAF) and monitor logs for suspicious activity, such as task=include requests, CSV-related AJAX activity, or unexplained file deletions.

These vulnerabilities were identified by security researcher p1r0x in collaboration with SSD Secure Disclosure. Administrators are urged to implement the recommended updates and security measures promptly to prevent potential exploitation.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories