CVE-2023-28731
PoC —CVSS 3.1
9.8 critical
EPSS
2%p77
Published
()
Modified
Description
AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to unrestricted file upload allowing PHP code to be injected. This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.
- Vendors
- acymailing
- Products
- acymailing
- Ecosystems
- Joomla
- Weakness
- CWE-20, CWE-434
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.