What the vulnerability does
01Description
Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated attacker could download files from both inside and outside the webroot.
CVSS base score
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
What the vulnerability does
Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated attacker could download files from both inside and outside the webroot.
Explanation of Vulnerability in Simple Terms
The SEBLOD extension for Joomla contains a path traversal vulnerability that allows an attacker to read arbitrary files from the server. An unauthenticated attacker can exploit this over the network without user interaction by crafting a malicious request. This could expose sensitive configuration files, database credentials, or other private data stored on the web server.
What an attacker can do
Read arbitrary files from the server, including configuration files and sensitive data.
Potential impact on your site
Attackers can access sensitive files like database credentials, configuration settings, and private user data.
Conditions required to exploit
Network access to the Joomla site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities