What the vulnerability does
01Description
Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the file upload action lead to path a traversal vulnerability.
CVSS base score
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N
What the vulnerability does
Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the file upload action lead to path a traversal vulnerability.
Explanation of Vulnerability in Simple Terms
Phoca Commander for Joomla contains a path traversal vulnerability that allows an attacker with high-level privileges to read or modify files outside the intended directory. The vulnerability requires administrative access to exploit. Site owners should update to a patched version when available.
What an attacker can do
Read or modify files outside the intended directory on the server.
Potential impact on your site
An admin account compromise could allow file system access beyond the extension's scope.
Conditions required to exploit
Attacker must have high-level administrative privileges in Joomla.
Key dates
External resources
Related vulnerabilities