CVE-2018-6580

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
02/02/2018
Last modified:
14/02/2018

Description

Arbitrary file upload exists in the Jimtawl 2.1.6 and 2.2.5 component for Joomla! via a view=upload&task=upload&pop=true&tmpl=component request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:janguo:jimtawl:2.1.6:*:*:*:*:joomla\!:*:*
cpe:2.3:a:janguo:jimtawl:2.2.5:*:*:*:*:joomla\!:*:*


References to Advisories, Solutions, and Tools