PT-2017-18051 · Open Source Matters · Joomla!
Abdullah Hussam
·
Published
2017-04-25
·
Updated
2017-05-02
·
CVE-2017-7989
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Joomla! versions 3.2.0 through 3.6.5
Description
The issue arises from inadequate MIME type checks, allowing low-privilege users to upload swf files even if they were explicitly forbidden.
Recommendations
For versions 3.2.0 through 3.6.5, update to version 3.7.0 to resolve the issue.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Joomla!