PT-2019-18737 · Joomla · Joomla!
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Joomla! versions prior to 3.9.3
Description
An issue was discovered where the phar:// stream wrapper can be used for object injection attacks due to the lack of a protection mechanism. This allows the phar:// handler to be used for non .phar-files, potentially leading to exploitation.
Recommendations
For versions prior to 3.9.3, update to version 3.9.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the phar:// stream wrapper to minimize the risk of object injection attacks.
Fix
DoS
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Joomla!