CVE-2018-17856
EUVD-2022-341109.10.2018, 21:29
An issue was discovered in Joomla! before 3.8.13. com_joomlaupdate allows the execution of arbitrary code. The default ACL config enabled the ability of Administrator-level users to access com_joomlaupdate and trigger code execution.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| joomla | joomla\! | 2.5.4 ≤ 𝑥 < 3.8.13 |
𝑥
= Vulnerable software versions
References