CVE-2015-7339: Malicious File Upload
Published Mar 9, 2020
·Updated
JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /comjce/editor/libraries/classes/browser.php script.
Affected Software
1 affected component
Widgetfactorylimited Jce Joomla\!>=2.5.0<=2.5.2
Event History
Mar 9, 2020
CVE Published
via MITRE·04:23 PM
Data Sourced
via MITRE·04:23 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7339?
CVE-2015-7339 has a high severity due to its ability to allow arbitrary file uploads, potentially compromising the security of the Joomla site.
2
How do I fix CVE-2015-7339?
To fix CVE-2015-7339, update the JCE component to a version later than 2.5.2 that addresses this vulnerability.
3
Which Joomla versions are affected by CVE-2015-7339?
CVE-2015-7339 affects Joomla Content Editor (JCE) versions 2.5.0 to 2.5.2.
4
What impact does CVE-2015-7339 have on my Joomla site?
CVE-2015-7339 can lead to unauthorized file uploads, which may allow attackers to execute malicious scripts on your Joomla site.
5
Is there a workaround for CVE-2015-7339?
A practical workaround for CVE-2015-7339 is to disable the JCE component until an update can be applied.