VDB
Sign up
HIGH7.2

GHSA-9m72-pw47-292w

Joomla RCE Vulnerability

Quick fix

GHSA-9m72-pw47-292w — joomla/framework: upgrade to the fixed version with the command below.

composer require joomla/framework:^3.8.13

Details

An issue was discovered in Joomla! before 3.8.13. com_joomlaupdate allows the execution of arbitrary code. The default ACL config enabled the ability of Administrator-level users to access com_joomlaupdate and trigger code execution.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/joomla/framework
Introduced in: 2.5.4Fixed in: 3.8.13
Fixcomposer require joomla/framework:^3.8.13

References