vendor:
JSSupportTicket
by:
qw3rTyTy
7.5
CVSS
HIGH
Authenticated Arbitrary File Deletion
264
CWE
Product Name: JSSupportTicket
Affected Version From: 1.1.6
Affected Version To: 1.1.6
Patch Exists: NO
Related CWE: N/A
CPE: a:joomsky:jssupportticket:1.1.6
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Debian/nginx/joomla 3.9.0
2019
Joomla! component com_jssupportticket – Authenticated Arbitrary File Deletion
This vulnerability is caused when processing custom user field. An authenticated user can delete arbitrary files on the server by sending a crafted POST request to the vulnerable file.
Mitigation:
Ensure that user input is properly validated and sanitized before being used in file operations.