Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

OVH falsely flags Joomla backup connector as malware

mySites.guru says OVH mistakenly identified the legitimate Joomla bfnetwork connector file bfRestore.php as malware.

In a June 22 write-up, mySites.guru said the flagged file is part of its connector extension for audits, backups, updates and restores. The vendor says bfRestore.php is password-gated and passes restore requests to Joomla’s core com_joomlaupdate extraction code.

The incident is described as a false-positive malware detection rather than a vulnerability in the extension. The report says OVH’s response disabled website access, PHP email and outbound connections across affected hosting plans. It reports no compromise or exploitation.

No affected or fixed extension versions, CVE identifiers or formal severity rating are provided. Administrators who received an OVH alert naming bfnetwork/bfRestore.php should not delete the file. Instead, they should use the OVH control panel to lift the security measures, then test forms, password resets and Joomla update checks. If the block returns, mySites.guru recommends opening an OVH support ticket and requesting that the specific file be whitelisted.

Originally reported by mySites.guru.