← All CVEs

CVE-2020-23972

high · 7.5

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can also upload files which due to issues of unrestricted file uploads which can be bypassed by changing the content-type and name file too double extensions.

7.5
CVSS
31.4%
EPSS (exploit prob.)
98th
EPSS percentile
2020-08-27
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Weaknesses

CWE-434

Affected products

VendorProductAffected versions
gmapfpgmapfpj3.5
gmapfpgmapfpj3.5

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-23972