CVE-2015-7341: Malicious File Upload
Published Mar 9, 2020
·Updated
JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers or Templates, as demonstrated by the .php5 extension.
Affected Software
1 affected component
Joobi Jnews Joomla\!<8.5.0
Event History
Mar 9, 2020
CVE Published
via MITRE·04:17 PM
Data Sourced
via MITRE·04:17 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7341?
CVE-2015-7341 has a high severity rating due to the potential for arbitrary file uploads.
2
How do I fix CVE-2015-7341?
To fix CVE-2015-7341, update the JNews Joomla Component to version 8.5.0 or later.
3
What is the impact of CVE-2015-7341?
CVE-2015-7341 allows attackers to upload arbitrary files, possibly leading to a compromise of the web server.
4
Which versions of JNews are affected by CVE-2015-7341?
CVE-2015-7341 affects JNews Joomla Component versions prior to 8.5.0.
5
Is my Joomla site vulnerable to CVE-2015-7341?
If you are using JNews Joomla Component version lower than 8.5.0, your site is vulnerable to CVE-2015-7341.