CVE-2021-23132: [20210306] - Core - com_media allowed paths that are not intended for image uploads
Published Mar 4, 2021
·Updated
An issue was discovered in Joomla! 3.0.0 through 3.9.24. commedia allowed paths that are not intended for image uploads
Affected Software
1 affected component
Joomla Joomla\!>=3.0.0<3.9.25
Event History
Mar 4, 2021
CVE Published
via MITRE·05:37 PM
Data Sourced
via MITRE·05:37 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-23132.
2
What is the severity of CVE-2021-23132?
The severity of CVE-2021-23132 is high with a severity value of 7.5.
3
What is the affected software for CVE-2021-23132?
The affected software for CVE-2021-23132 is Joomla! versions 3.0.0 through 3.9.24.
4
What is the impact of CVE-2021-23132?
CVE-2021-23132 allows paths that are not intended for image uploads in the com_media component of Joomla!, which can potentially lead to unauthorized access to sensitive files.
5
How can I fix CVE-2021-23132?
To fix CVE-2021-23132, update Joomla! to version 3.9.25 or higher.