vendor:
JSSupportTicket
by:
qw3rTyTy
8.8
CVSS
HIGH
Arbitrary File Download
434
CWE
Product Name: JSSupportTicket
Affected Version From: 1.1.5
Affected Version To: 1.1.5
Patch Exists: YES
Related CWE: N/A
CPE: cpe:a:joomsky:jssupportticket:1.1.5
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Debian/nginx/joomla 3.9.0
2019
Joomla! component com_jssupportticket – Arbitrary File Download
A vulnerability in the Joomla! component com_jssupportticket allows an attacker to download arbitrary files from the server. This is due to the lack of proper input validation in the getDownloadAttachmentByName() function in the file admin/models/ticket.php. An attacker can craft a malicious URL to download any file from the server.
Mitigation:
Upgrade to the latest version of the Joomla! component com_jssupportticket.