vendor:
Joomla! Plugin XCloner Backup
by:
Mehmet Kelepçe / Gais Cyber Security
7.5
CVSS
HIGH
Local File Inclusion
22
CWE
Product Name: Joomla! Plugin XCloner Backup
Affected Version From: 3.5.2003
Affected Version To: 3.5.2003
Patch Exists: YES
Related CWE:
CPE: a:xcloner:xcloner_backup:3.5.3
Platforms Tested: Kali Linux - Apache2
2020
Joomla! Plugin XCloner Backup 3.5.3 – Local File Inclusion (Authenticated)
The Joomla! Plugin XCloner Backup 3.5.3 allows an authenticated user to include local files on the server by manipulating the 'file' parameter in the 'download' action of the 'admin.cloner.php' file. This can lead to unauthorized access and disclosure of sensitive information.
Mitigation:
Upgrade to the latest version of the Joomla! Plugin XCloner Backup.