CVE-2026-78079: Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in Helix Ultimate < 2.2.10
Joomla Extension - joomshaper.com - Open Redirect via Base64 Return Parameter in Helix Ultimate < 2.2.10 - Return redirect parameters accepted arbitrary Base64 strings without verifying whether the resolved target was an internal site URL via Uri::isInternal.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Joomla Extension - joomshaper.com - Helix Ultimateto a version that resolves this vulnerability.Fixed in 2.2.10
Event History
Frequently Asked Questions
What versions are affected?
Helix Ultimate versions earlier than 2.2.10 are affected.
What does an attacker need to exploit this issue?
An attacker needs to supply a return redirect parameter containing an arbitrary Base64-encoded value. The parameter is accepted without verifying that its resolved destination is an internal site URL.
How can exposure be reduced before updating?
The provided information identifies the return redirect parameter as the affected input, but does not provide a documented workaround or configuration mitigation. Prioritize updating Helix Ultimate to 2.2.10 or later.