What the vulnerability does
01Description
Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the getSource function lead to an arbitrary file read vulnerability.
CVSS base score
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
What the vulnerability does
Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the getSource function lead to an arbitrary file read vulnerability.
Explanation of Vulnerability in Simple Terms
Phoca Commander for Joomla contains a path traversal vulnerability that allows an attacker with high-level privileges to read files outside the intended directory. The vulnerability requires network access and high administrative privileges. An attacker can access sensitive files on the server by manipulating file paths.
What an attacker can do
Read files outside the intended directory on the server.
Potential impact on your site
An admin account with high privileges could be compromised to access sensitive server files.
Conditions required to exploit
Attacker must have high-level administrative privileges on the Joomla site.
Key dates
External resources
Related vulnerabilities