ZeroHour

CVE-2023-28731

PoC
CVSS 3.1
9.8 critical
EPSS
2%p77
Published
()
Modified
Description

AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to unrestricted file upload allowing PHP code to be injected. This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.

Vendors
acymailing
Products
acymailing
Ecosystems
Joomla
Weakness
CWE-20, CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.