Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Event Gallery 6.5.0 fixes eight Joomla security issues

Event Gallery 6.5.0 fixes eight security issues in the Joomla extension, including upload CSRF, reflected XSS and guessable cart and order identifiers.

mySites.guru published research on the release from vendor Sven Bluege, identifying issues in Event Gallery versions below 6.5.0. The fixed release is 6.5.0.

  • Missing CSRF protection could let a malicious page upload or replace permitted images through a logged-in editor’s session.
  • A crafted frontend upload link could trigger reflected XSS in an editor’s session.
  • Cart and order identifiers could be inferred from creation times.
  • Several backend actions also lacked token or permission checks.

The write-up does not list CVE identifiers or provide a formal severity rating, and it does not report active exploitation. Administrators should update Event Gallery on every affected site. Release 6.5.0 requires Joomla 5.4 or later, so Joomla 3 and 4 sites must upgrade their CMS first. Sites using a template override for the upload layout should update that override as well.

Originally reported by mySites.guru.