RSFirewall Component Path Traversal Vulnerability in Joomla

Vulnerability

A path traversal vulnerability has been identified in the RSFirewall component for Joomla, specifically in versions 2.9.7 through 3.1.5. This vulnerability allows authenticated users to read arbitrary files located outside the Joomla root directory. The issue arises from inadequate sanitization of user-supplied input in file path parameters, enabling attackers to exploit directory traversal sequences to access sensitive files.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive files on the server, potentially exposing confidential information or application data.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.