Описание
Joomla RCE Vulnerability
An issue was discovered in Joomla! before 3.8.13. com_joomlaupdate allows the execution of arbitrary code. The default ACL config enabled the ability of Administrator-level users to access com_joomlaupdate and trigger code execution.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2018-17856
- https://developer.joomla.org/security-centre/752-20181002-core-inadequate-default-access-level-for-com-joomlaupdate.html
- https://web.archive.org/web/20210124211736/http://www.securityfocus.com/bid/105559
- https://web.archive.org/web/20211208125303/http://www.securitytracker.com/id/1041914
Пакеты
Наименование
joomla/framework
composer
Затронутые версииВерсия исправления
>= 2.5.4, <= 3.8.12
3.8.13
Связанные уязвимости
CVSS3: 7.2
nvd
больше 7 лет назад
An issue was discovered in Joomla! before 3.8.13. com_joomlaupdate allows the execution of arbitrary code. The default ACL config enabled the ability of Administrator-level users to access com_joomlaupdate and trigger code execution.