PT-2020-17364 · Joomla · Joomla!

Lee Thao

+1

·

Published

2020-12-28

·

Updated

2025-04-03

·

CVE-2020-35612

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Joomla! versions 2.5.0 through 3.9.22
Description An issue was discovered in the folder parameter of mod random image, which lacked input validation, leading to a path traversal vulnerability.
Recommendations For Joomla! versions 2.5.0 through 3.9.22, update to a version that includes the fix for the path traversal vulnerability in the mod random image module. As a temporary workaround, consider restricting access to the mod random image module to minimize the risk of exploitation.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BIT-JOOMLA-2020-35612
CVE-2020-35612

Affected Products

Joomla!