Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x9hv-www7-w846

Опубликовано: 12 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9

Описание

Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenticated users could perform various file-related operations (read, delete, overwrite, re-assign permissions) on every file managed within the extension.

Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenticated users could perform various file-related operations (read, delete, overwrite, re-assign permissions) on every file managed within the extension.

EPSS

Процентиль: 16%
0.00247
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-284

Связанные уязвимости

nvd
7 дней назад

Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenticated users could perform various file-related operations (read, delete, overwrite, re-assign permissions) on every file managed within the extension.

EPSS

Процентиль: 16%
0.00247
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-284