PT-2018-17644 · Joomla · Jimtawl
Ihsan Sencan
·
Published
2018-02-02
·
Updated
2018-02-14
·
CVE-2018-6580
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Jimtawl versions 2.1.6 through 2.2.5
Description
The issue allows for arbitrary file upload in the Jimtawl component for Joomla. This can be achieved through a request to the "view=upload&task=upload&pop=true&tmpl=component" endpoint.
Recommendations
For Jimtawl version 2.1.6, update to a version that contains a fix for this issue.
For Jimtawl version 2.2.5, update to a version that contains a fix for this issue.
As a temporary workaround, consider restricting access to the upload functionality in the Jimtawl component until a patch is available.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jimtawl