PT-2023-21925 · Joomla · Anymailing Joomla Plugin

Raphaël Arrouas

+1

·

Publicado

2023-03-30

·

Atualizado

2023-04-06

·

CVE-2023-28731

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AnyMailing Joomla Plugin Enterprise versions prior to 8.3.0
Description The issue is related to unauthenticated remote code execution when access to campaign creation is granted on the front-office, due to unrestricted file upload allowing PHP code injection.
Recommendations For versions prior to 8.3.0, update to version 8.3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the campaign creation feature on the front-office to minimize the risk of exploitation. Avoid using the unrestricted file upload feature until the issue is resolved.

Exploit

Correção

RCE

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-28731

Produtos afetados

Anymailing Joomla Plugin