V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2019-10945
CVE
CriticalConfirmedExploit available

An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder parameter, allowing atta…

CVSS
9.8
Critical
EPSS
0.38
p98
Published
2019-01-01
Updated
2019-01-01
Description

An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder parameter, allowing attackers to act outside the media manager root directory.

Tags · CWE
Pre-auth
CWE-22
CAPEC-64
CAPEC-76
CAPEC-78
CAPEC-79
CAPEC-126
Affected products
Joomla\! 1.5.0–3.9.4
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2019-01-01
Published
2019-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.380 · p98
Known exploited (KEV)
No
Known exploits — Сканер-ВС
46710
exploitdb · https://www.exploit-db.com/exploits/46710
Enterprise
CVE-2019-10945
github-poc · https://github.com/tayW84/CVE-2019-10945----Python3
Enterprise
Affected products
ProductVendorStatus
joomla!*Tracked
Source databases
CVE