CVE-2019-10945
critical · 9.8An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder parameter, allowing attackers to act outside the media manager root directory.
9.8
CVSS
38.0%
EPSS (exploit prob.)
98th
EPSS percentile
2019-04-10
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-22
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| joomla | joomla! | >= 1.5.0, <= 3.9.4 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/152515/Joomla-3.9.4-Arbitrary-File-Deletion-Directory-Traversal.html
- https://developer.joomla.org/security-centre/777-20190401-core-directory-traversal-in-com-media
- https://www.exploit-db.com/exploits/46710/
- http://packetstormsecurity.com/files/152515/Joomla-3.9.4-Arbitrary-File-Deletion-Directory-Traversal.html
- https://developer.joomla.org/security-centre/777-20190401-core-directory-traversal-in-com-media
- https://www.exploit-db.com/exploits/46710/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2019-10945