ZeroHour

CVE-2020-23971

PoC
CVSS 3.1
7.5 high
EPSS
2%p74
Published
()
Modified
Description

gmapfp.org Joomla Component GMapFP J3.30pro is affected by Insecure Permissions. An attacker can access the upload function without authenticating to the application and also can upload files due the issues of unrestricted file uploads which can be bypassed by changing the content-type and name file too double extensions.

Vendors
gmapfp
Products
gmapfp
Ecosystems
Joomla
Weakness
CWE-276
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.