What the vulnerability does
01Description
AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to unrestricted file upload allowing PHP code to be injected.
This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.
Explanation of Vulnerability in Simple Terms
02Summary
AcyMailing Enterprise for Joomla versions before 8.3.0 contain an input validation flaw that allows unauthenticated attackers to run their own code on the site, read sensitive data, or disrupt service. No user interaction is required. The vulnerability affects all versions from 0 to 8.3.0.
What an attacker can do
03Attacker Capabilities
Run code on the site, read sensitive data, or disrupt service without authentication.
Potential impact on your site
04Site Impact
Attackers can compromise your Joomla site, steal data, or take it offline without needing a user account.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
March 30, 2023
CVE published
February 11, 2025
Record updated