What the vulnerability does
01Description
Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group.
CVSS base score
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
What the vulnerability does
Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group.
Explanation of Vulnerability in Simple Terms
The Zoo extension for Joomla contains an unrestricted file upload vulnerability that allows attackers to upload files with dangerous types without authentication. An attacker can upload malicious files (such as PHP scripts) directly to the server, leading to remote code execution. This affects Zoo versions 1.0.0-4.1.63 and earlier. Sites running this extension are at critical risk.
What an attacker can do
Upload and execute malicious files on the server, gaining full control of the Joomla site.
Potential impact on your site
Complete compromise of the Joomla installation; attacker can read/modify/delete all data and user accounts.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities