CVE-2020-10934: Malicious File Upload
Published Mar 24, 2020
·Updated
Acyba AcyMailing before 6.9.2 mishandles file uploads by admins.
Affected Software
1 affected component
Acyba Acymailing Joomla\!<6.9.2
Event History
Mar 24, 2020
CVE Published
via MITRE·02:55 PM
Data Sourced
via MITRE·02:55 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-10934?
CVE-2020-10934 is considered a high severity vulnerability due to its potential for arbitrary file uploads by admins.
2
How do I fix CVE-2020-10934?
To fix CVE-2020-10934, update AcyMailing to version 6.9.2 or later.
3
What types of systems are affected by CVE-2020-10934?
CVE-2020-10934 affects instances of AcyMailing before version 6.9.2 running on Joomla.
4
What is the nature of the flaw in CVE-2020-10934?
The flaw in CVE-2020-10934 is a mishandling of file uploads by administrators, allowing potential malicious file uploads.
5
Who is impacted by CVE-2020-10934?
Website administrators using vulnerable versions of AcyMailing are impacted by CVE-2020-10934.