Menu
Band aid

We made some security analysis with Claude in the last days and are shipping today fixes for these issues. Gladly there is no issue which allows to place files on the server or any other way to compromise a site.

This is an exceptional Thursday as normally we release on the fourth of the month. Today, we are releasing the following security updates:

Each affected extension contains one High-severity security issue, so we strongly recommend updating immediately. This is particularly important for DPAttachments, where attachments can be downloaded without authentication. We therefore recommend prioritizing this update. For the other vulnerabilities, exploitation generally requires some level of administrative access or interaction with content from a trusted source. In practice, this makes exploitation considerably less likely. For example, it is uncommon for an author to upload a CSV file containing JavaScript code in its titles, or for a trusted event source to provide attachment names specifically crafted to exploit path traversal vulnerabilities.

Nevertheless, security vulnerabilities should not be ignored simply because the conditions required for exploitation are unusual. A vulnerability that appears difficult to exploit today may become easier to exploit once more information about it becomes publicly available. We therefore recommend updating all affected extensions as soon as possible. Staying up to date ensures that your website benefits from the latest security fixes and provides the best protection against both known and emerging threats. We now list some more general details about the issues for each extension.

DPCalendar

In DPCalendar we fixed the following issues:

  • [High] Location title is not escaped in map view and upcoming module, which can lead to XSS when user can create locations
  • [Medium] Normalize filenames for Microsoft events 365 attachments, happens only for attachments on an integrated account
  • [Medium] Extra protection with a state variable for external calendar imports to prevent CSRF 

DPMedia

In DPMedia we fixed the following issues:

  • [High] DPReferences shows references for users without media manager access
  • [Medium] Path traversal outside of root with dots in external file names, this is more of a hardening as it can't be misused due other checks
  • [Medium] Google Drive search injection
  • [Medium] Extra protection with a state variable for account (Google, Dropbox) imports to prevent CSRF 

DPAttachments

In DPAttachments we fixed the following issues:

  • [High] Unauthorized access to direct downloads
  • [Medium] Stored XSS in CSV preview from headers in CSV file
  • [Medium] Upload context validation for extra XSS injection validation

DPCases

In DPCases we fixed the following issues:

  • [High] Escape user information in views to prevent XSS
  • [Medium] No path traversal for icons outside of root

Conclusion

These vulnerabilities were discovered during our own internal security audits. As far as we know, there is currently no evidence that they have been exploited in the wild. The issues primarily affect our paid extensions. Because the source code of these extensions is not publicly available, discovering and analyzing potential vulnerabilities requires significantly more effort for attackers. This means that, in many cases, we are likely to identify and address vulnerabilities before they can be discovered and exploited by others. However, this should not be taken as a reason to delay updating.

Once a vulnerability becomes publicly known, the risk can change quickly, as attackers may use the published information to investigate older versions and develop exploits. We therefore strongly recommend that you update all affected extensions as soon as possible, even if you have no indication that your website has been compromised. Keeping your extensions up to date is one of the most important measures you can take to protect your Joomla website. We will continue to proactively audit our extensions and address security issues as soon as they are identified.

A full changelog is added in the respective download release description on our download site.

Kind regards

Allon Moritz aka laoneo
Founder of Digital Peak