Overview
An authenticated attacker may be able to upload active content to websites running older versions of Joomla.
Description
CWE-434: Unrestricted Upload of File with Dangerous Type A vulnerability has been discovered in older versions of the Joomla! content management software that allow an authenticated attacker to upload active content through the media manager form ('administrator/components/com_media/helpers/media.php'). Joomla! allows files with a trailing '.' to pass the upload checks.
|
Impact
The complete impact of this vulnerability is not yet known. |
Solution
Apply an Update |
Restrict Access |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 8.5 | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Temporal | 6.7 | E:POC/RL:OF/RC:C |
Environmental | 5.3 | CDP:L/TD:M/CR:ND/IR:ND/AR:ND |
References
- http://osvdb.org/show/osvdb/95933
- http://developer.joomla.org/security/563-20130801-core-unauthorised-uploads.html
- http://joomlacode.org/gf/project/joomla/tracker/?action=TrackerItemEdit&%20tracker_item_id=31626
- https://github.com/joomla/joomla-cms/commit/fa5645208eefd70f521cd2e4d53d5378622133d8
- http://niiconsulting.com/checkmate/2013/08/critical-joomla-file-upload-vulnerability/
- http://www.exploit-db.com/exploits/27610/
- http://blog.sucuri.net/2013/08/joomla-media-manager-attacks-in-the-wild.html
- http://www.cso.com.au/article/523528/joomla_patches_file_manager_vulnerability_responsible_hijacked_websites/
Acknowledgements
Thanks to Versafe for reporting this vulnerability.
This document was written by Todd Lewellen.
Other Information
CVE IDs: | CVE-2013-5576 |
Date Public: | 2013-07-31 |
Date First Published: | 2013-10-30 |
Date Last Updated: | 2013-10-30 15:40 UTC |
Document Revision: | 16 |