QID 11739
Date Published: 2021-03-30
QID 11739: Joomla Core Multiple Vulnerabilities(20210308, 20210307, 20210306)
Joomla is a free and open-source content management system written in PHP. It uses object oriented programming techniques and is built on a model-view-controller web application framework. It includes features such as page caching, RSS feeds, printable versions of pages, news flashes, blogs, polls, search, and support for language internationalization.
Affected Version:
Joomla! CMS versions 3.0.0 - 3.9.24
Fixed Version:
Upgrade to version 3.9.25
QID Detection Logic(Unauthenticated):
QID checks for the Vulnerable version of Joomla.
Successful exploitation could allow unauthorized change of the category for an article, com_media allowed paths that are not intended for image uploads, Extracting an specifilcy crafted zip package could write files outside of the intended path.
- 20210306 -
developer.joomla.org/security-centre/846-20210306-core-com-media-allowed-paths-that-are-not-intended-for-image-uploads.html - 20210307 -
developer.joomla.org/security-centre/847-20210307-core-acl-violation-within-com-content-frontend-editing.html - 20210308 -
developer.joomla.org/security-centre/848-20210308-core-path-traversal-within-joomla-archive-zip-class.html