PT-2018-10481 · Open Source Matters · Joomla!

Demis Palma

·

Published

2018-05-22

·

Updated

2018-06-22

·

CVE-2018-11322

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Joomla! Core versions prior to 3.8.8
Description An issue was discovered that could allow PHAR files to be handled as executable PHP scripts by the webserver, depending on the server configuration.
Recommendations For versions prior to 3.8.8, update to version 3.8.8 or later to resolve the issue.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-11322

Affected Products

Joomla!