CVE-2018-11322: Malicious File Upload
Published May 22, 2018
·Updated
An issue was discovered in Joomla! Core before 3.8.8. Depending on the server configuration, PHAR files might be handled as executable PHP scripts by the webserver.
Affected Software
1 affected component
Joomla Joomla\!<3.8.8
Event History
May 22, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-11322?
CVE-2018-11322 has been classified as a high severity vulnerability due to the potential for remote code execution if exploited.
2
How do I fix CVE-2018-11322?
To fix CVE-2018-11322, upgrade your Joomla! Core to version 3.8.8 or later.
3
What kind of impact does CVE-2018-11322 have on Joomla?
CVE-2018-11322 can lead to unauthorized code execution on servers using vulnerable Joomla versions.
4
In which versions of Joomla is CVE-2018-11322 found?
CVE-2018-11322 affects Joomla! Core versions prior to 3.8.8.
5
Are PHAR files safe to use with Joomla according to CVE-2018-11322?
PHAR files can be unsafe with affected versions of Joomla! as they may be treated as executable scripts, leading to security risks.