vendor:
Joomla
by:
Gary @ Sec-1 ltd
8,8
CVSS
HIGH
Object Injection
502
CWE
Product Name: Joomla
Affected Version From: 3.4.4
Affected Version To: 3.4.4
Patch Exists: YES
Related CWE: CVE-2015-8562
CPE: a:joomla:joomla
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
Joomla Object Injection
Joomla is vulnerable to Object Injection, which allows attackers to inject malicious objects into the application. This can be exploited to execute arbitrary PHP code by passing a specially crafted payload to the vulnerable application. This vulnerability affects Joomla versions prior to 3.4.5.
Mitigation:
Upgrade to Joomla version 3.4.5 or later.