CVE-2023-28731

AnyMailing Joomla Plugin is vulnerable tounauthenticated remote code execution,when being granted access to the campaign's creation on front-office due to unrestricted file upload allowing PHP code to be injected. 



This issue affects AnyMailing Joomla PluginEnterprise in versions below 8.3.0. 










ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NCSC.chCNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---