vendor:
Joomla
by:
Jose Antonio Rodriguez Garcia and Phil Keeble (MWR InfoSecurity)
9.8
CVSS
CRITICAL
CSV Injection
CWE
Product Name: Joomla
Affected Version From: 3.9.2000
Affected Version To: 3.9.2007
Patch Exists: YES
Related CWE: CVE-2019-12765
CPE:
Platforms Tested: Ubuntu 18.04 LTS and Windows 7
2020
Joomla 3.9.0 < 3.9.7 - CSV Injection
This exploit allows an attacker to inject malicious code into a CSV file in Joomla versions 3.9.0 to 3.9.7. By registering a new user with a specially crafted name, the attacker can execute arbitrary commands on the target system.
Mitigation:
Update to Joomla version 3.9.7 or later to mitigate this vulnerability.