Security
Helix3 3.1.1 fixes critical Joomla security flaws
JoomShaper has released Helix3 3.1.1 to address critical security vulnerabilities that could let unauthenticated attackers write and delete files on Joomla servers.
The affected component is the plg_ajax_helix3 plugin in Helix3, with versions before 3.1.1 affected. mySites.guru published the research after finding the issues while investigating a hacked customer site and reported them to JoomShaper through responsible disclosure.
The flaws include unauthenticated file writing, arbitrary file deletion and template-parameter overwriting. The release also hardens image uploads, path handling and output escaping, addressing additional code-execution, cross-site scripting and abuse risks. The vulnerable handler was reachable through Joomla’s com_ajax dispatcher without requiring a login.
mySites.guru rates the update as critical. Its analysis says the issue affects current Joomla 4, 5 and 6 installations using Helix3. The write-up does not identify a CVE, and reports that the compromise investigation provided evidence of real-world impact.
Administrators should update every site using Helix3 to 3.1.1 immediately. Helix Ultimate is a separate product and is not affected by this issue.
Originally reported by mySites.guru.