Joomla! CMS
cpe:2.3:a:joomla:joomla!:*:*:*:*:*:*:*
- >= 4.0.0, <= 4.4.11
- >= 5.0.0, <= 5.2.4
A vulnerability in the Joomla! Media Manager allows users with edit privileges to upload files with arbitrary extensions, including executable PHP files. This issue arises from inadequate validation of file extensions, potentially leading to the execution of malicious scripts.
Exploitation of this vulnerability allows for the upload of malicious files that could be executed on the server, potentially leading to a compromise of the web application or the underlying server.
Users are advised to upgrade to Joomla! version 4.4.12 or 5.2.5.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.