vendor:
Joomla!
by:
Egidio Romano
7,5
CVSS
HIGH
PHP Object Injection
502
CWE
Product Name: Joomla!
Affected Version From: 3.0.2 and earlier 3.0.x versions, 2.5.8 and earlier 2.5.x versions
Affected Version To: None
Patch Exists: YES
Related CWE: CVE-2013-1453
CPE: None
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2013
Joomla! <= 3.0.2 (highlight.php) PHP Object Injection Vulnerability
User input passed through the 'highlight' parameter is not properly sanitized before being used in an unserialize() call at line 58. This can be exploited to inject arbitrary PHP objects into the application scope. Successful exploitation of this vulnerability doesn't require authentication, but requires the 'System Highlight' plugin to be enabled (such as by default configuration).
Mitigation:
Upgrade to version 3.0.3 or 2.5.9.