vendor:
com_wmtportfolio
by:
NoGe
7.5
CVSS
HIGH
Remote File Include
98
CWE
Product Name: com_wmtportfolio
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
wmtportfolio joomla component 1.0 Remote File Include Vulnerability
The vulnerability is found in the com_wmtportfolio component version 1.0 of Joomla. It allows an attacker to include a remote file by manipulating the 'mosConfig_absolute_path' parameter in the 'admin.wmtportfolio.php' file. This can lead to remote code execution on the server.
Mitigation:
To mitigate this vulnerability, it is recommended to update the com_wmtportfolio component to a patched version or remove the component if not needed.