Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wjv4-xh6c-w4j7

Опубликовано: 11 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9

Описание

The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.

The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.

EPSS

Процентиль: 44%
0.00543
Низкий

9 Critical

CVSS4

Дефекты

CWE-434

Связанные уязвимости

nvd
около 2 месяцев назад

The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.

EPSS

Процентиль: 44%
0.00543
Низкий

9 Critical

CVSS4

Дефекты

CWE-434