PT-2026-77200 · Joomla · Joomla!
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Joomla! Core versions 1.0.0 through 5.4.7
Joomla! Core versions 6.0.0 through 6.1.2
Description
The software fails to include SHTML files in its default list of dangerous files, allowing unrestricted uploads of these files. On servers configured to execute SHTML files, this can lead to remote code execution.
Recommendations
Update Joomla! Core versions 1.0.0 through 5.4.7 to a version newer than 5.4.7.
Update Joomla! Core versions 6.0.0 through 6.1.2 to a version newer than 6.1.2.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Joomla!