What the vulnerability does
01Description
Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.
CVSS base score
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
What the vulnerability does
Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.
Explanation of Vulnerability in Simple Terms
A high-privilege vulnerability in Joomla! CMS 4.0.0 through 5.4.3 allows authenticated administrators to read sensitive data on the site. The vulnerability requires an admin account and network access but does not require user interaction. Site administrators should update to a version newer than 5.4.3 as soon as a patch is available.
What an attacker can do
Read sensitive data on the Joomla site if they have administrator privileges.
Potential impact on your site
An admin account holder can access confidential information; monitor admin accounts and restrict access to trusted users only.
Conditions required to exploit
Attacker must have administrator-level access to the Joomla site.
Key dates
External resources
Related vulnerabilities