An issue was discovered in Joomla! before 3.8.12. Inadequate checks in the InputFilter class could allow specifically prepared phar files to pass the upload filter.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/105166 | third party advisory vdb entry |
https://developer.joomla.org/security-centre/743-20180801-core-hardening-the-inputfilter-for-phar-stubs.html | vendor advisory |
http://www.securitytracker.com/id/1041913 | third party advisory vdb entry |