QID 154107
Date Published: 2022-05-20
QID 154107: Joomla! Core Arbitrary File Write via Archive Extraction (Zip Slip) Vulnerability (CVE-2022-23793)
Joomla! is a free and open-source content management system for publishing web content on websites.
Affected versions of this package are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) via the Joomla\Archive\Tar::extract() function, as a result of improper verification of the destination path.
Affected Versions:
Joomla 3.0.0 to 3.10.6
Joomla 4.0.0 to 4.1.0
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Joomla installed on the target.
A remote attacker can send a specially crafted archive to the web application and write files outside of the intended path.
Solution
Customers are advised to install latest Joomla version.
For more information visit Joomla security advisory [20220301].
For more information visit Joomla security advisory [20220301].
Vendor References
- [20220301] - Core - Zip Slip within the Tar extractor -
developer.joomla.org/security-centre/870-20220301-core-zip-slip-within-the-tar-extractor.html
CVEs related to QID 154107
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| [20220301] - Core - Zip Slip within the Tar extractor |
|