VDB
Sign up
CRITICAL9.8

GHSA-5m3w-rvvh-8fx6

Joomla! Object Injection Vulnerability

Quick fix

GHSA-5m3w-rvvh-8fx6 — joomla/joomla-cms: upgrade to the fixed version with the command below.

composer require joomla/joomla-cms:^3.9.3

Details

An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for object injection attacks because there is no protection mechanism (such as the TYPO3 PHAR stream wrapper) to prevent use of the phar:// handler for non .phar-files.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/joomla/joomla-cms
Introduced in: 2.5.0Fixed in: 3.9.3
Fixcomposer require joomla/joomla-cms:^3.9.3

References