HIGH7.2
GHSA-9m72-pw47-292w
Joomla RCE Vulnerability
Quick fix
GHSA-9m72-pw47-292w — joomla/framework: upgrade to the fixed version with the command below.
composer require joomla/framework:^3.8.13Details
An issue was discovered in Joomla! before 3.8.13. com_joomlaupdate allows the execution of arbitrary code. The default ACL config enabled the ability of Administrator-level users to access com_joomlaupdate and trigger code execution.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/joomla/framework
Introduced in:
2.5.4Fixed in: 3.8.13Fix
composer require joomla/framework:^3.8.13References
- https://nvd.nist.gov/vuln/detail/CVE-2018-17856[ADVISORY]
- https://developer.joomla.org/security-centre/752-20181002-core-inadequate-default-access-level-for-com-joomlaupdate.html[WEB]
- https://github.com/joomla/joomla-cms[PACKAGE]
- https://web.archive.org/web/20210124211736/http://www.securityfocus.com/bid/105559[WEB]
- https://web.archive.org/web/20211208125303/http://www.securitytracker.com/id/1041914[WEB]