vendor:
GMapFP
by:
ThelastVvV
7.5
CVSS
HIGH
Unauthenticated Arbitrary File Upload
434
CWE
Product Name: GMapFP
Affected Version From: Version J3.5
Affected Version To: Version J3.5free
Patch Exists: YES
Related CWE: CVE-2020-23972
CPE: a:gmapfp:gmapfp:3.5
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu
2020
Joomla! Component GMapFP 3.5 – Unauthenticated Arbitrary File Upload
An attacker can access the upload function of the application without authenticating to the application and also can upload files due the issues of unrestricted file uploads which can be bypassed by changing the content-type and name file too double extensions.
Mitigation:
Update to the latest version of the application.