Description
An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for objection injection attacks because there is no protection mechanism (such as the TYPO3 PHAR stream wrapper) to prevent use of the phar:// handler for non .phar-files.
Remediation
References
Related Vulnerabilities
Ruby on Rails Deserialization of Untrusted Data Vulnerability (CVE-2018-16476)
Oracle Database Server CVE-2009-3413 Vulnerability (CVE-2009-3413)
WordPress Plugin WP-Optimize Multiple Vulnerabilities (1.8.9.9)
TCExam Observable Differences in Behavior to Error Inputs Vulnerability (CVE-2021-20113)
Oracle Application Server Other Vulnerability (CVE-2007-2123)