Fwd: Update RSFiles! now: an unauthenticated flaw let anyone run code on your site

0 views
Skip to first unread message

Dorothy Firsching

unread,
Jul 10, 2026, 11:48:32 AM (12 days ago) Jul 10
to Bruce Scherzinger, Dwayne Grimes, Frankee Nilsen, CD Guillaudeu, Gene Crawford, novaj...@googlegroups.com
Another vulnerability

---------- Forwarded message ---------
From: Phil Taylor <ph...@phil-taylor.com>
Date: Fri, Jul 10, 2026 at 11:08 AM
Subject: Update RSFiles! now: an unauthenticated flaw let anyone run code on your site
To: <dfirs...@acm.org>


RSFiles! up to 1.17.11 let an anonymous visitor upload a PHP file and run code on your server. I found it, reported it privately, and the fix is out. Update to 1.17.12 now.
mySites.guru
 

Found by mySites.guru · Fix available

RSFiles! just fixed a flaw that let a stranger run code on your site

RSFiles! is a widely used file and download manager for Joomla. Up to and including version 1.17.11, its frontend upload could be reached by anyone, with no login and no security token, and the code that actually wrote the file to disk checked nothing about its type. Put those together and an anonymous visitor could upload a .php file into the public downloads folder and then run it, which is remote code execution, the worst outcome a web flaw can have.

I found this during a routine source audit of the extensions our customers rely on, proved the whole chain end to end on a local Joomla install, and reported it privately to RSJoomla before saying a word in public. They replied the same day, shipped the fix in RSFiles! 1.17.12, and published a clear advisory telling site owners to update now. A CVE has been requested and is pending. No proof of concept has been made public, so this isn't a recipe going out ahead of the fix.

If you run any Joomla site with RSFiles! on it, update every one to 1.17.12 or later today. This isn't a wait-for-the-next-maintenance-window job. Any site still on 1.17.11 or earlier is reachable by anyone on the internet, so update it, then check the downloads folder for stray files and your admin user list for accounts you don't recognise, because an unauthenticated upload leaves no login trail behind.

The full write-up, including what the fix changes, is free to read on the blog

 

How the flaw worked, and how to check your sites

RSFiles! unauthenticated file upload RCE fixed in 1.17.12

The checks RSFiles! does have, a permission gate and a file-type allow-list, lived in a pre-flight step that writes nothing, while the method that actually saved the file ran no checks and trusted the filename the caller sent. It's the same class of flaw, an unauthenticated file upload, that was fixed recently in Balbooa Forms, iCagenda, Page Builder CK and JCE. The post walks through what was wrong, what 1.17.12 changes, and exactly what to look for on a site that sat on an old version, without publishing anything an attacker could copy.

Read the full breakdown

If you manage more than a handful of Joomla sites, mySites.guru lists every RSFiles! install in your account, so you can see at a glance which ones still need the update.

 
Phil Taylor

Need help with your site?

Phil Taylor – Fixing websites since 2004

Found something wrong with your Joomla or WordPress site? If it were simple, you'd have fixed it already. I offer same-day expert help at a flat rate of £120 per incident. No hourly billing surprises.

✓ Hacked or compromised sites
✓ PHP errors and white screens
✓ Upgrades and PHP 8 compatibility
✓ Performance and hosting issues
Get expert help today

If I can't add value, you don't pay

mySites.guru

Website management since 2012

 

Reply all
Reply to author
Forward
0 new messages