QID 730637
Date Published: 2022-11-09
QID 730637: Joomla Multiple Security Vulnerabilities (20220301, 20220302 and 20220305)
Joomla is a free and open-source content management system written in PHP. It uses object oriented programming techniques and is built on a model-view-controller web application framework. It includes features such as page caching, RSS feeds, printable versions of pages, news flashes, blogs, polls, search, and support for language internationalization.
CVE-2022-23793: Extracting an specifilcy crafted tar package could write files outside of the intended path.
CVE-2022-23794: Uploading a file name of an excess length causes the error. This error brings up the screen with the path of the source code of the web application.
CVE-2022-23797: Inadequate filtering on the selected Ids on an request could resulted into an possible SQL injection.
Affected Version:
Joomla! CMS versions from 3.0.0 to 3.10.6
Joomla! CMS versions from 4.0.0 to 4.1.0
Fixed Version:
Upgrade to version 3.10.7 and 4.1.1
QID Detection Logic(Unauthenticated):
QID checks for the Vulnerable version of Joomla.
Successful exploitation would lead to the disclosure of the path of the source code of the web application or can send a specially crafted archive to the web application and write files outside of the intended path.
- 20220301, 20220302 and 20220305 -
developer.joomla.org/security-centre.html
CVEs related to QID 730637
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 20220301, 20220302 and 20220305 |
|