vendor:
JiFile
by:
Mr Winst0n
7.5
CVSS
HIGH
Arbitrary File Download
22
CWE
Product Name: JiFile
Affected Version From: 2.3.2001
Affected Version To: 2.3.2001
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Kali linux, Windows 8.1
2019
Joomla! Component JiFile 2.3.1 – Arbitrary File Download
The Joomla! Component JiFile version 2.3.1 is vulnerable to an arbitrary file download. An attacker can exploit this vulnerability to download arbitrary files from the target system.
Mitigation:
Update to the latest version of JiFile component or remove the component if not needed.