CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution
The US Cybersecurity and Infrastructure Security Agency CISA on Tuesday added a maximumseverity security flaw impacting Widget Factory Joomla Content Editor JCE to its Known Exploited Vulnerabilities KEV catalog citing evidence of active exploitation The vulnerability tracked as CVE202648907 CVSS score 100 is a case of improper access control that could facilitate arbitrary