Joomla Novarain/Tassos Framework Vulnerabilities Enables SQL injection and Unauthenticated File Read
Websites utilizing the Novarain/Tassos Framework are subject to significant security vulnerabilities that enable unauthorized file reading, file deletion, and SQL injection attacks. These vulnerabilities could lead to remote code execution and complete…
Websites utilizing the Novarain/Tassos Framework are subject to significant security vulnerabilities that enable unauthorized file reading, file deletion, and SQL injection attacks. These vulnerabilities could lead to remote code execution and complete administrative control if systems remain unpatched. Immediate updates from the vendor are required to mitigate these risks.
An analysis of the Novarain/Tassos Framework plugin (plg_system_nrframework) revealed three critical vulnerabilities. These are exposed through an AJAX handler that processes the task=include action without adequate security measures.
Attackers can exploit PHP classes under the Joomla site root, leveraging the onAjax method to access internal helper classes as remotely accessible gadgets. CSV loading is improperly handled, allowing reading of arbitrary files accessible to the webserver user. A remove action is exposed, enabling deletion of attacker-supplied paths without validation. Dynamic field population passes attacker-controlled parameters into database queries, resulting in an SQL injection vulnerability.
These vulnerabilities can be chained to allow attackers to steal administrator session data, access the backend, and deploy malicious extensions or modify templates, leading to persistent remote code execution (RCE).
The framework is integrated into several popular Joomla extensions, including:
These vulnerabilities could lead to remote code execution and complete administrative control if systems remain unpatched.
Convert Forms (v3.2.12 – v5.1.0) EngageBox (v6.0.0 – v7.1.0) Google Structured Data (v5.1.7 – v6.1.0) Advanced Custom Fields (v2.2.0 – v3.1.0) Smile Pack (v1.0.0 – v2.1.0)
The vulnerabilities affect the Novarain/Tassos Framework (plg_system_nrframework) versions v4.10.14 to v6.0.37. Exploitation is possible if the system plugin is enabled on internet-facing sites. The attack vector uses unauthenticated AJAX requests, necessitating additional security measures.
The vendor has released patched versions of the affected framework and extensions, available via the official downloads section and Joomla update mechanisms. Administrators are advised to update all Tassos components immediately or disable the plg_system_nrframework plugin and related extensions temporarily.
As a precaution, operators should restrict or filter com_ajax traffic at the web server or Web Application Firewall (WAF) and monitor logs for suspicious activity, such as task=include requests, CSV-related AJAX activity, or unexplained file deletions.
These vulnerabilities were identified by security researcher p1r0x in collaboration with SSD Secure Disclosure. Administrators are urged to implement the recommended updates and security measures promptly to prevent potential exploitation.
Based on reporting by Cyber Security News.
