Description
An issue was discovered in Joomla! before 3.8.13. com_joomlaupdate allows the execution of arbitrary code. The default ACL config enabled the ability of Administrator-level users to access com_joomlaupdate and trigger code execution.
Remediation
References
Related Vulnerabilities
WordPress Plugin Google Analytics MU Cross-Site Request Forgery (2.3.1)
Craft CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-41892)
WeBid Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-7117)
Oracle Database Server CVE-2014-4296 Vulnerability (CVE-2014-4296)