CVE-2023-28731: Unauthenticated RCE affecting the AcyMailing plugin for Joomla
AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to unrestricted file upload allowing PHP code to be injected.
This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-28731?
CVE-2023-28731 is a vulnerability in the AnyMailing Joomla Plugin that allows unauthenticated remote code execution.
How does CVE-2023-28731 affect AnyMailing Joomla Plugin?
CVE-2023-28731 affects AnyMailing Joomla Plugin Enterprise versions below 8.3.0.
Can an attacker execute arbitrary code remotely with CVE-2023-28731?
Yes, an attacker can execute arbitrary code remotely by exploiting the CVE-2023-28731 vulnerability in the AnyMailing Joomla Plugin.
What is the severity of CVE-2023-28731?
CVE-2023-28731 has a severity rating of 9.8 (critical).
How can I fix CVE-2023-28731?
To fix CVE-2023-28731, you should update AnyMailing Joomla Plugin Enterprise to version 8.3.0 or above.