QID 154107

Date Published: 2022-05-20

QID 154107: Joomla! Core Arbitrary File Write via Archive Extraction (Zip Slip) Vulnerability (CVE-2022-23793)

Joomla! is a free and open-source content management system for publishing web content on websites.

Affected versions of this package are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) via the Joomla\Archive\Tar::extract() function, as a result of improper verification of the destination path.

Affected Versions:
Joomla 3.0.0 to 3.10.6
Joomla 4.0.0 to 4.1.0

QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Joomla installed on the target.

A remote attacker can send a specially crafted archive to the web application and write files outside of the intended path.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to install latest Joomla version.
    For more information visit Joomla security advisory [20220301].
    Vendor References

    CVEs related to QID 154107

    Software Advisories
    Advisory ID Software Component Link
    [20220301] - Core - Zip Slip within the Tar extractor URL Logo developer.joomla.org/security-centre/870-20220301-core-zip-slip-within-the-tar-extractor.html