CVE-2013-5576: Input Validation
administrator/components/commedia/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 allows remote authenticated users or remote attackers to bypass intended access restrictions and upload files with dangerous extensions via a filename with a trailing . (dot), as exploited in the wild in August 2013.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5576?
CVE-2013-5576 is classified as a high severity vulnerability due to its potential for file upload exploits.
How do I fix CVE-2013-5576?
To fix CVE-2013-5576, upgrade Joomla! to version 2.5.14 or 3.1.5 or later.
What systems are affected by CVE-2013-5576?
CVE-2013-5576 affects Joomla! versions 2.5.x before 2.5.14 and 3.x before 3.1.5.
What type of attack does CVE-2013-5576 allow?
CVE-2013-5576 allows remote authenticated users or attackers to bypass access restrictions and upload files with malicious extensions.
Can CVE-2013-5576 lead to a website compromise?
Yes, exploiting CVE-2013-5576 can lead to unauthorized file uploads, potentially compromising the website.