PT-2021-16921 · Joomla · Joomla!

Lee Jinheon

+1

·

Published

2021-03-04

·

Updated

2025-04-03

·

CVE-2021-26028

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Joomla! versions 3.0.0 through 3.9.24
Description An issue was discovered where extracting a specifically crafted zip package could write files outside of the intended path.
Recommendations For Joomla! versions 3.0.0 through 3.9.24, update to a version that contains a fix for this issue.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BIT-JOOMLA-2021-26028
CVE-2021-26028
GHSA-VGWR-773Q-7J3C

Affected Products

Joomla!