
JoomGallery TUS upload: no login, write into temp, steal someone else’s in-flight file!!! CVE-2026-84048: JoomGallery 4.0.0–4.4.1 accepted unauthenticated TUS uploads. Filename/extension are not attacker-chosen, so this is not a clean webshell drop. Any visitor can still plant files in temp and read/delete another upload mid-flight!! Real patch is 4.4.2 https://mysites.guru/blog/joomgallery-unauthenticated-file-upload/ #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #Joomla #AppSec #FileUpload
