CVE-2020-23971

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/09/2020
Last modified:
08/09/2020

Description

gmapfp.org Joomla Component GMapFP J3.30pro is affected by Insecure Permissions. An attacker can access the upload function without authenticating to the application and also can upload files due the issues of unrestricted file uploads which can be bypassed by changing the content-type and name file too double extensions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gmapfp:gmapfp:j3.30:*:*:*:pro:joomla\!:*:*