What the vulnerability does
01Description
Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.1 - Improper limitation of paths for save and download actions lead to path traversal vulnerabilities.
CVSS base score
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
What the vulnerability does
Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.1 - Improper limitation of paths for save and download actions lead to path traversal vulnerabilities.
Explanation of Vulnerability in Simple Terms
Phoca Commander for Joomla contains a path traversal vulnerability that allows an attacker with high-level privileges to read files outside the intended directory. The vulnerability requires network access and high administrative privileges. Site administrators should update to a patched version when available.
What an attacker can do
Read files outside the intended directory on the server.
Potential impact on your site
An admin account could be compromised to access sensitive files like configuration or database backups.
Conditions required to exploit
Attacker must have high-level administrative privileges and network access to the Joomla site.
Key dates
External resources
Related vulnerabilities