What the vulnerability does
01Description
Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths for delete, copy and move actions lead to path traversal vulnerabilities.
CVSS base score
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
What the vulnerability does
Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths for delete, copy and move actions lead to path traversal vulnerabilities.
Explanation of Vulnerability in Simple Terms
Phoca Commander for Joomla contains a path traversal vulnerability that allows authenticated administrators to read or modify files outside the intended directory. An attacker with high-level admin privileges can navigate the file system using specially crafted paths. This affects versions 1.0.0 through 6.1.3. Update to a version newer than 6.1.3 when available.
What an attacker can do
Read or modify files outside the intended directory on the server.
Potential impact on your site
A compromised admin account could expose sensitive files or alter site configuration and data.
Conditions required to exploit
Attacker must have high-level administrator privileges in Joomla.
Key dates
External resources
Related vulnerabilities