First published: Thu Mar 04 2021(Updated: )
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path.
Credit: security@joomla.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/joomla/archive | <1.1.10 | |
Joomla Joomla\! | >=3.0.0<3.9.25 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26028 is a vulnerability in Joomla! that allows an attacker to write files outside of the intended path when extracting a specially crafted zip package.
The severity of CVE-2021-26028 is medium, with a severity value of 5.5.
Joomla! versions 3.0.0 through 3.9.24 are affected by CVE-2021-26028.
An attacker can exploit CVE-2021-26028 by providing a specially crafted zip package and extracting it within Joomla!.
Yes, a fix is available for CVE-2021-26028. Users should update Joomla! to version 3.9.25 or higher.